A JWT issued to an Org 1 account is accepted on the Org 2 API and can read the admin-only GraphQL participantDetails field for an Org 2 participant. The same trust-boundary problem also affects API-user authentication: an Org 1 API user can use a JWT on the Org 1 host and replay that JWT to the Org 2 API to read Org 2 participant personal data and reach Org 2's proposal.answer mutation path.
The current host selects the Decidim organization context, but JWT-backed API authentication is not sufficiently bound to that host organization. As a result, the API can process a request in Org 2's context while still trusting an authenticated principal from Org 1.
Reproduction steps:
org2.localhost:3001Note that using a participant-generated JWT did not allow showing these results.
A JWT issued for one organization can be replayed successfully against another organization's API and used to retrieve sensitive details from that organization.
See https://github.com/decidim/decidim/pull/16673 and https://github.com/decidim/decidim/pull/16756
Disable JWT credentials on system panel (/system)
OWASP A01:2021 Broken Access Control
This issue was discovered in a security audit organized by the [Decidim...
0.31.50.32.0Exploitability
AV:NAC:LPR:LUI:NScope
S:CImpact
C:HI:LA:N8.5/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N