Skip to main content

Changelog

Updates, changes, and improvements at Retool.

Refer to the stable and edge release notes for detailed information about self-hosted releases.

Spaces Deletion IDOR

An Insecure Direct Object Reference (IDOR) vulnerability was discovered that allowed admins of one space to delete any space or organization on a Retool instance. Attackers leveraging this vulnerability could execute a DoS attack by deleting a target space.

To exploit this vulnerability, an attacker would need to have an active account with permissions to manage at least one space on an instance.

DetailDescription
Vulnerability TypeCWE-284: Improper Access Control
Attack TypeRemote
ImpactDeletion of target spaces

Affected and patched release versions

Retool has already patched this vulnerability on Retool Cloud and released the following patches for Stable and Edge channel releases of self-hosted Retool.

ChannelAffected versionPatched version
Edge3.11.0 and earlier3.312.0
3.284 Stable3.284.0 to 3.284.73.284.8
3.253 Stable3.253.0 to 3.253.153.253.16