[LOW]
·
Intigriti
·
Resolved
Duplicate
BFLA ---- on GraphQL ListAvailableRoles query allows unauthorize access to low privileged user
The affected asset is anonymised at the researcher's request.
Summary
The GraphQL endpoint cloud.digitalocean.com/graphql is vulnerable to Broken Function Level Authorization (BFLA). A user with low-level privileges (e.g., Billing role) can successfully execute the ListAvailableRoles query, which should be restricted to administrators or users with team management permissions. This allows the disclosure of sensitive custom role metadata, including names, UUIDs, and granular permissions.
Impact
Violation of Least Privilege: A billing user should not have visibility into the security configurations or custom RBAC (Role-Based Access Control) structures of the organization.