The Script That Granted Everyone Everything — JavaScript Bug Hunt

Modelled on the Salesforce Pardot incident (May 2019): a database script intended to adjust permissions for one feature applied a broad grant instead,…

  • Language: JavaScript
  • Layer: Database
  • Difficulty: Medium
  • Concepts: Permissions, Scoping
  • Modelled on: Salesforce Pardot · 2019
  • Visible tests: only in-scope users are granted; an empty scope changes nobody
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Salesforce Pardot incident (May 2019): a database script intended to adjust permissions for one feature applied a broad grant instead, giving every user in affected orgs read and write access to all company data. Salesforce shut the service down for over 15 hours while it unwound the change.

grants.js applies a permission change and ignores the scope it was given.

Fix applyGrant so it only touches users inside the requested scope.

Bug report

BUG-PARDOT · Priority: Critical (data exposure) · Reported by: trust & safety

applyGrant(users, scope, permission) must:

  • set permission on users whose orgId is in scope.orgIds AND whose role is in scope.roles
  • leave every other user's permissions exactly as they were
  • return the number of users changed

Observed: the scope is accepted but never consulted; every user in the store is granted the permission.

Logs

[grants] applied "write:all" to 100% of users (scope requested: 1 org, role=admin)
[grants] service disabled pending remediation

The code as shipped

src/authz/grants.js (editable)

// Applies a permission grant to the users in scope.
exports.applyGrant = function (users, scope, permission) {
  var changed = 0;
  for (var i = 0; i < users.length; i++) {
    var u = users[i];
    if (u.permissions.indexOf(permission) === -1) {
      u.permissions.push(permission);
      changed++;
    }
  }
  return changed;
};

Read-only context: src/authz/POLICY.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.