---
cve: "CVE-2024-55954"
severity: "HIGH"
cvss: 8.7
epss: "0.5%"
vendor: "openobserve"
kev: false
exploited: false
published: "2025-01-16 20:15:32"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-25T23:32:55+02:00"
---

# CVE-2024-55954

> 8.7 HIGH · 🧪 PoC

## Beschreibung

OpenObserve is a cloud-native observability platform. A vulnerability in the user management endpoint `/api/{org_id}/users/{email_id}` allows an "Admin" role user to remove a "Root" user from the organization. This violates the intended privilege hierarchy, enabling a non-root user to remove the highest-privileged account. Due to insufficient role checks, the `remove_user_from_org` function does not prevent an "Admin" user from removing a "Root" user. As a result, an attacker with an "Admin" role can remove critical "Root" users, potentially gaining effective full control by eliminating the highest-privileged accounts. The `DELETE /api/{org_id}/users/{email_id}` endpoint is affected. This issue has been addressed in release version `0.14.1` and all users are advised to upgrade. There are no known workarounds for this vulnerability.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- adc52c1ed1c2147b891b3a9a40943dd7992565bb (Commit)

## Referenzen

- <https://github.com/openobserve/openobserve/security/advisories/GHSA-m8gj-6r85-3r6m>
- <https://github.com/gaby/openobserve/blob/main/src/service/users.rs#L631>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-55954) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
