piccolo-admin Privilege Escalation Issue: Early Warning
- Severity
- HIGH
- Affected component
- piccolo-admin (pypi)
- Affected versions
- < 1.14.0 or >= 0.1.0, <= 0.1.0 or >= 0.1.1, <= 0.1.1 or >= 0.1.2, <= 0.1.2 or >= 0.1.3, <= 0.1.3 or >= 0.1.4, <= 0.1.4 or >= 0.10.0, <= 0.10.0 or >= 0.10.1, <= 0.10.1 or >= 0.10.2, <= 0.10.2 or >= 0.10.3, <= 0.10.3 or >= 0.10.4, <= 0.10.4 or >= 0.10.5, <= 0.10.5 or >= 0.10.6, <= 0.10.6 or >= 0.10.7, <= 0.10.7 or >= 0.10.8, <= 0.10.8 or >= 0.10.9, <= 0.10.9 or >= 0.11.0, <= 0.11.0 or >= 0.11.1, <= 0.11.1 or >= 0.11.10, <= 0.11.10 or >= 0.11.11, <= 0.11.11 or >= 0.11.12, <= 0.11.12 or >= 0.11.13, <= 0.11.13 or >= 0.11.2, <= 0.11.2 or >= 0.11.3, <= 0.11.3 or >= 0.11.4, <= 0.11.4 or >= 0.11.5, <= 0.11.5 or >= 0.11.6, <= 0.11.6 or >= 0.11.7, <= 0.11.7 or >= 0.11.8, <= 0.11.8 or >= 0.11.9, <= 0.11.9 or >= 0.12.0, <= 0.12.0 or >= 0.12.1, <= 0.12.1 or >= 0.13.0, <= 0.13.0 or >= 0.13.1, <= 0.13.1 or >= 0.13.2, <= 0.13.2 or >= 0.14.0, <= 0.14.0 or >= 0.15.0, <= 0.15.0 or >= 0.15.1, <= 0.15.1 or >= 0.15.2, <= 0.15.2 or >= 0.16.0, <= 0.16.0 or >= 0.16.1, <= 0.16.1 or >= 0.17.0, <= 0.17.0 or >= 0.18.0, <= 0.18.0 or >= 0.18.1, <= 0.18.1 or >= 0.18.2, <= 0.18.2 or >= 0.19.0, <= 0.19.0 or >= 0.19.1, <= 0.19.1 or >= 0.19.2, <= 0.19.2 or >= 0.19.3, <= 0.19.3 or >= 0.19.4, <= 0.19.4 or >= 0.19.5, <= 0.19.5 or >= 0.19.6, <= 0.19.6 or >= 0.2.0, <= 0.2.0 or >= 0.20.0, <= 0.20.0 or >= 0.21.0, <= 0.21.0 or >= 0.22.0, <= 0.22.0 or >= 0.22.1, <= 0.22.1 or >= 0.22.2, <= 0.22.2 or >= 0.23.0, <= 0.23.0 or >= 0.24.0, <= 0.24.0 or >= 0.25.0, <= 0.25.0 or >= 0.26.0, <= 0.26.0 or >= 0.26.1, <= 0.26.1 or >= 0.27.0, <= 0.27.0 or >= 0.28.0, <= 0.28.0 or >= 0.29.0, <= 0.29.0 or >= 0.29.1, <= 0.29.1 or >= 0.3.0, <= 0.3.0 or >= 0.3.1, <= 0.3.1 or >= 0.3.2, <= 0.3.2 or >= 0.3.3, <= 0.3.3 or >= 0.3.4, <= 0.3.4 or >= 0.3.5, <= 0.3.5 or >= 0.3.6, <= 0.3.6 or >= 0.3.7, <= 0.3.7 or >= 0.3.8, <= 0.3.8 or >= 0.30.0, <= 0.30.0 or >= 0.31.0, <= 0.31.0 or >= 0.31.1, <= 0.31.1 or >= 0.31.2, <= 0.31.2 or >= 0.32.0, <= 0.32.0 or >= 0.33.0, <= 0.33.0 or >= 0.33.1, <= 0.33.1 or >= 0.34.0, <= 0.34.0 or >= 0.35.0, <= 0.35.0 or >= 0.36.0, <= 0.36.0 or >= 0.37.0, <= 0.37.0 or >= 0.38.0, <= 0.38.0 or >= 0.39.0, <= 0.39.0 or >= 0.4.0, <= 0.4.0 or >= 0.4.1, <= 0.4.1 or >= 0.40.0, <= 0.40.0 or >= 0.41.0, <= 0.41.0 or >= 0.42.0, <= 0.42.0 or >= 0.43.0, <= 0.43.0 or >= 0.44.0, <= 0.44.0 or >= 0.45.0, <= 0.45.0 or >= 0.45.1, <= 0.45.1 or >= 0.45.2, <= 0.45.2 or >= 0.46.0, <= 0.46.0 or >= 0.47.0, <= 0.47.0 or >= 0.48.0, <= 0.48.0 or >= 0.49.0, <= 0.49.0 or >= 0.5.0, <= 0.5.0 or >= 0.5.1, <= 0.5.1 or >= 0.50.0, <= 0.50.0 or >= 0.51.0, <= 0.51.0 or >= 0.52.0, <= 0.52.0 or >= 0.53.0, <= 0.53.0 or >= 0.54.0, <= 0.54.0 or >= 0.55.0, <= 0.55.0 or >= 0.56.0, <= 0.56.0 or >= 0.57.0, <= 0.57.0 or >= 0.58.0, <= 0.58.0 or >= 0.6.0, <= 0.6.0 or >= 0.6.1, <= 0.6.1 or >= 0.6.2, <= 0.6.2 or >= 0.6.3, <= 0.6.3 or >= 0.6.4, <= 0.6.4 or >= 0.6.5, <= 0.6.5 or >= 0.6.6, <= 0.6.6 or >= 0.7.0, <= 0.7.0 or >= 0.8.0, <= 0.8.0 or >= 0.8.1, <= 0.8.1 or >= 0.9.0, <= 0.9.0 or >= 0.9.1, <= 0.9.1 or >= 0.9.2, <= 0.9.2 or >= 1.0.0, <= 1.0.0 or >= 1.1.0, <= 1.1.0 or >= 1.1.1, <= 1.1.1 or >= 1.1.2, <= 1.1.2 or >= 1.1.3, <= 1.1.3 or >= 1.10.0, <= 1.10.0 or >= 1.11.0, <= 1.11.0 or >= 1.12.0, <= 1.12.0 or >= 1.13.0, <= 1.13.0 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.3.2, <= 1.3.2 or >= 1.3.3, <= 1.3.3 or >= 1.4.0, <= 1.4.0 or >= 1.5.0, <= 1.5.0 or >= 1.6.0, <= 1.6.0 or >= 1.7.0, <= 1.7.0 or >= 1.7.1, <= 1.7.1 or >= 1.8.0, <= 1.8.0 or >= 1.8.1, <= 1.8.1 or >= 1.8.2, <= 1.8.2 or >= 1.9.0, <= 1.9.0 or >= 1.9.1, <= 1.9.1 or >= 1.2.0, < 1.3.2 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1 or >= 1.2.0, < 1.3.2 or >= 1.2.0, <= 1.2.0 or >= 1.2.1, <= 1.2.1 or >= 1.2.2, <= 1.2.2 or >= 1.3.0, <= 1.3.0 or >= 1.3.1, <= 1.3.1
- Patched version
- Not yet available
An early warning has been issued for a privilege escalation issue in the piccolo-admin package. This issue allows non-superuser admins to access live session tokens in plaintext, enabling them to impersonate users and self-promote to superuser.
What happened
The piccolo-admin package reportedly has a critical vulnerability that permits non-superuser admins to access live session tokens in plaintext. This flaw is due to the lack of rejection for GET requests in the superuser_validators function. The issue is under investigation and has not yet been exploited in the wild. The affected versions span a wide range, from versions less than 1.14.0 to various versions between 0.1.0 and 1.3.2.
This vulnerability poses a significant risk as it allows unauthorized admins to gain superuser privileges by impersonating legitimate users. The exposure assessment should focus on identifying which versions of piccolo-admin are in use within your systems and determining if any non-superuser admins have access to the affected endpoints.
What to do about it
- Review your use of the piccolo-admin package and identify the versions currently in deployment.
- Ensure that GET requests are properly restricted in the superuser_validators function to prevent unauthorized access to session tokens.
- Consider implementing additional security measures to safeguard session tokens from unauthorized access.
- Monitor the primary sources for updates on the vulnerability and any official fixes that may be released.
- No official fix has been published yet. Continue to monitor the sources below for updates.
How 0Day would have caught this
piccolo-admin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using piccolo-admin versions less than 1.14.0 or any version between 0.1.0 and 1.3.2.
What should I do right now?
Review your piccolo-admin package versions, restrict GET requests in the superuser_validators function, and implement additional security measures for session tokens. Monitor primary sources for updates.
Is there an official fix available?
No official fix has been published yet. Continue to monitor the sources for updates.
How can I prevent unauthorized access to session tokens?
Ensure proper restriction of GET requests in the superuser_validators function and implement additional security measures as recommended.