openwisp-ipam
IP address space administration module of OpenWISP
Activity
- Latest release
- 1w ago
- Total releases
- 10
- Cadence
- ~3 months
- Last 12 months
- 4
Reach
- Stars
- 120
Details
- License
- BSD-3-Clause
- First release
- May 28, 2020
| Version | Released | |
|---|---|---|
1.3.1
patch
| ||
1.3
minor
| ||
1.2.1
minor
| ||
1.2.post1
pre
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev | ||
1.1.1
patch
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev | ||
1.1
minor
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev | ||
1.0
major
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev | ||
0.2
minor
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev | ||
0.1.1
patch
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev | ||
0.1
initial
1 CVE
GHSA-x287-5c68-36wp
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
5.3
/ 10
Medium
Network
High
Low
None
Unchanged
High
None
None
SummaryOpenWISP IPAM is multi-tenant: every Details
The The same single-object pattern (resolving the subnet by Proof of conceptPrerequisites: an OpenWISP IPAM instance with two organizations OrgA and OrgB; a normal (non-superuser) user who is a member of OrgB only; a subnet in OrgA whose id
(Reported from a first-hand source review of the current ImpactA member of one organization can read the complete contents of another organization's subnet — its IP allocation inventory (addresses, descriptions, organization slug, CIDR). In a WISP / network-management deployment this discloses another tenant's network topology and host inventory. Exploitation requires obtaining the target subnet's UUID (AC:H), but the authorization check is missing outright. ( RemediationAdd the organization-membership check to Affected versions
0.1
0.1.1
0.2
1.0
1.1
1.1.1
1.2.post1
Fixed in
1.2.1
References
Updated Aug 26, 2026 · Source: OSV.dev |