Skip to content

Choreo Security Bulletin – H2 2025

Published: 2026-09-22

Version: 1.0.0

BULLETIN ID

CHO-SB-2025-H2

SCOPE

This bulletin summarizes security vulnerabilities addressed during the H2 of 2025 for Choreo.

VULNERABILITIES ADDRESSED

Reference ID Title Severity Summary
CHO-2025-007 Read-Only Attribute Modification via SCIM2/Me API Medium A user attribute configured as read-only in the UI could still be modified through the SCIM2 /Me API because the restriction was enforced only at the UI layer and not at the backend/API layer. This could lead administrators to incorrectly assume sensitive attributes were protected from end-user modification. The issue was remediated by clarifying the product behavior in the UI and documentation to accurately reflect the scope of the read-only configuration.
CHO-2025-008 Cross-Organization Authorization Bypass Critical A cross-organization authorization gap allowed a user with a valid token and required scopes to perform privileged operations against other organizations, including adding themselves as an administrator, inviting users, managing groups, and removing group members. The issue was caused by the broader-than-intended removal of the isAdmin() check during migration. It was rated CVSS 9.4 (Critical), remediated through a production hotfix in the US and EU, and no evidence of exploitation or customer impact was identified.
CHO-2025-009 Unsecured Choreo Build Workflow Endpoint Medium An unsecured public /configurable-commit-mapping endpoint allowed unauthenticated modification of source and GitOps commit mappings used by the Choreo CI/CD workflow. Exploitation required several specific deployment identifiers, and successful exploitation could disrupt configuration-management and deployment actions, while existing running workloads remained unaffected. The issue was rated CVSS 4.8 (Medium) and was remediated in production.
CHO-2025-010 API Access Remains Active After Lifecycle State Change Medium APIs and services could continue to be invoked using existing client credentials and API keys even after their lifecycle state was changed from Published to states such as Created, Blocked, or Retired. This meant API accessibility did not consistently reflect the configured lifecycle state. Similar behavior was reported in Devant and Bijira, with investigation required to confirm whether the same root cause applied across the products. The issue has since been fixed.
CHO-2025-011 Potential Exposure to Compromised NPM Packages Medium Following the compromise of widely used NPM packages associated with the qix maintainer, several Choreo repositories were identified as using potentially affected dependencies such as color, debug, chalk, and related packages. The incident was raised for impact assessment and remediation, including dependency review, package updates, and monitoring for unusual activity. Subsequent analysis determined that Choreo was not vulnerable to the reported supply-chain compromise.
CHO-2025-012 Content Spoofing via Organization Name Parameter Medium The organization name supplied through the invitation flow was reflected directly on the login page without sufficient input sanitization or trusted backend validation, allowing an attacker to manipulate the text displayed to users. This could be used to spoof organization-related login messaging during invitation acceptance. The issue was remediated by changing the frontend to use the organization handle and name returned by the trusted member-invitation validation endpoint instead of rendering organization information directly from user-controlled input.
CHO-2025-013 Stored Cross-Site Scripting via SVG Upload Medium A stored cross-site scripting vulnerability was identified in Choreo through uploaded SVG content, allowing malicious script content to be persisted and potentially executed when the affected asset was rendered. The issue was rated CVSS 6.1 (Medium). As an immediate remediation, SVG uploads were disabled because safely validating vector-based content was considered non-trivial, while other raster image formats remained supported. The fix was verified in the Choreo stage environment and has since been deployed to production.
CHO-2025-014 Denial of Service via Unrestricted OpenAPI File Processing High Choreo accepted and parsed OpenAPI/Swagger files from provided URLs without enforcing adequate file-size or file-type restrictions, allowing an attacker to repeatedly supply oversized files and exhaust resources in the APIM component. The issue was initially rated CVSS 7.5 (High), but further review confirmed that existing controls limited the availability impact and the CVSS score was subsequently revised to 5.3 (Medium). The fix was later deployed to production.
CHO-2025-015 Broken Access Control in Application Info Admin API Medium A broken access control issue was identified in Choreo’s get application info admin API endpoint, where insufficient validation could allow unauthorized access to application information. The issue was rated CVSS 5.8 (Medium). A fix was subsequently implemented and deployed to Choreo production, resolving the vulnerability.
CHO-2025-016 Cross-Tenant Theme Upload via Parameter Tampering High Improper validation of organization identifiers in the Choreo devportal-themes API allowed an authenticated user to tamper with request parameters and upload, retrieve, and publish a theme into another organization. This created a cross-tenant authorization issue where changes made by one organization could affect the target organization’s developer portal. The finding was assessed at CVSS 8.3 (High), and a fix was subsequently implemented and deployed to production.
CHO-2025-017 Denial of Service in Choreo Subscriptions API High A denial-of-service condition in the Ballerina version used by Choreo’s subscriptions service could be triggered by a crafted request containing a malformed path and an Authorization header, causing the service to become unresponsive. This could prevent subscription details from being retrieved during login and cause paid users to be treated as free users, creating both availability and business-impact concerns. Cloudflare-based filtering was applied as an interim mitigation, and the issue has since been permanently remediated and deployed to production so that the vulnerable request pattern can no longer reach the backend.
CHO-2025-018 AWS Instance Credential Exposure via SSRF High A server-side request forgery vulnerability in backend URL validation allowed requests to reach cloud metadata services, exposing AWS instance metadata and temporary IAM role credentials. The issue became Critical (CVSS 10) because the AWS environment was missing the NetworkPolicy required to block access to the metadata endpoint, while related Azure policies also contained configuration issues. A hotfix was applied to block metadata access, and updated NetworkPolicies were deployed across Azure US, Azure EU, and AWS and verified by engineering. Additional preventive work included extending network-policy coverage and adding connectivity tests to detect future regressions.
CHO-2025-019 Unrestricted File Upload Leading to Denial of Service Medium An unrestricted file upload issue could be abused to trigger a denial-of-service condition by allowing oversized or otherwise unsuitable files to be processed without adequate restrictions. The issue was rated CVSS 6.5 (Medium) and was confirmed to be reproducible across Choreo, Bijira, and Devant. Remediation was tracked separately by each product team, and fixes were subsequently deployed to production for all three products.

CREDITS

Choreo product team would like to thank all internal and external researchers for responsibly disclosing the above issues.