OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid simultaneously. This results in broken access control where a removed or demoted user can regain access or escalate privileges. This issue has been patched in version 0.16.0.
Metrics
Affected Vendors & Products
References
History
Sat, 29 Nov 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not expire once issued, remain valid even after the invited user is removed from the organization, and allow multiple invitations to the same email with different roles where all issued links remain valid simultaneously. This results in broken access control where a removed or demoted user can regain access or escalate privileges. This issue has been patched in version 0.16.0. | |
| Title | OpenObserve's Invite Token Lifecycle Misconfiguration | |
| Weaknesses | CWE-284 CWE-613 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-11-29T02:45:42.467Z
Updated: 2025-11-29T02:45:42.467Z
Reserved: 2025-11-24T23:01:29.679Z
Link: CVE-2025-66223
No data.
Status : Received
Published: 2025-11-29T03:16:00.227
Modified: 2025-11-29T03:16:00.227
Link: CVE-2025-66223
No data.
ReportizFlow