Critical Paperclip Flaw Allowed Admin Access, Code Execution

A previously unknown vulnerability in the Paperclip document management system has been discovered, potentially enabling an attacker to gain unauthorized access to administrative controls and execute malicious code.

A recently disclosed vulnerability in the Paperclip document management system has left security experts scrambling to update their systems to prevent exploitation. According to the advisory published by Synopsys, a leading provider of software security testing and verification services, the vulnerability, identified as CVE-2023-21239, allows an attacker to self-register, sign in for board-level API access, and import a new company for code execution.

The vulnerability, which was reported by a researcher, is attributed to a misconfigured authentication mechanism in the system's API. The researcher, who wished to remain anonymous, discovered the flaw while analyzing the system's code and testing its limits. The vulnerability is not specific to any particular version of Paperclip, but rather a generic issue that can be exploited by an attacker using a variety of techniques.

In response to the advisory, Paperclip's developers have released a patch to address the vulnerability, and users are advised to apply it immediately to prevent potential exploitation. Synopsys has also provided guidance on how to identify and remediate the vulnerability, as well as a list of known exploit code for the affected version of the system.

Source: Snyk Blog