The Script That Granted Everyone Everything — JavaScript Bug Hunt
Modelled on the Salesforce Pardot incident (May 2019): a database script intended to adjust permissions for one feature applied a broad grant instead,…
- Language: JavaScript
- Layer: Database
- Difficulty: Medium
- Concepts: Permissions, Scoping
- Modelled on: Salesforce Pardot · 2019
- Visible tests: only in-scope users are granted; an empty scope changes nobody
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Salesforce Pardot incident (May 2019): a database script intended to adjust permissions for one feature applied a broad grant instead, giving every user in affected orgs read and write access to all company data. Salesforce shut the service down for over 15 hours while it unwound the change.
grants.js applies a permission change and ignores the scope it was given.
Fix applyGrant so it only touches users inside the requested scope.
Bug report
BUG-PARDOT · Priority: Critical (data exposure) · Reported by: trust & safety
applyGrant(users, scope, permission) must:
- set permission on users whose orgId is in scope.orgIds AND whose role is in scope.roles
- leave every other user's permissions exactly as they were
- return the number of users changed
Observed: the scope is accepted but never consulted; every user in the store is granted the permission.
Logs
[grants] applied "write:all" to 100% of users (scope requested: 1 org, role=admin)
[grants] service disabled pending remediationThe code as shipped
src/authz/grants.js (editable)
// Applies a permission grant to the users in scope.
exports.applyGrant = function (users, scope, permission) {
var changed = 0;
for (var i = 0; i < users.length; i++) {
var u = users[i];
if (u.permissions.indexOf(permission) === -1) {
u.permissions.push(permission);
changed++;
}
}
return changed;
};
Read-only context: src/authz/POLICY.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.