Skip to main content

Changelog

Updates, changes, and improvements at Retool.

Refer to the stable and edge release notes for detailed information about self-hosted releases.

Spaces Deletion IDOR

An Insecure Direct Object Reference (IDOR) vulnerability was discovered that allowed admins of one space to delete any space or organization on a Retool instance. Attackers leveraging this vulnerability could execute a DoS attack by deleting a target space.

To exploit this vulnerability, an attacker would need to have an active account with permissions to manage at least one space on an instance.

DetailDescription
Vulnerability TypeCWE-284: Improper Access Control
Attack TypeRemote
ImpactDeletion of target spaces

Affected and patched release versions​

Retool has already patched this vulnerability on Retool Cloud and released the following patches for Stable and Edge channel releases of self-hosted Retool.

ChannelAffected versionPatched version
Edge3.11.0 and earlier3.312.0
3.284 Stable3.284.0 to 3.284.73.284.8
3.253 Stable3.253.0 to 3.253.153.253.16