Any user (including an anonymous user) can bypass APIv4 permission checks with a specially crafted REST call.
The vulnerability arises from a discrepancy in how capitalization is handled by JSON, PHP arrays, and PHP methods.
CiviCRM v6.16.3 and earlier
CiviCRM v6.17.0, v6.16.4, v6.10.9(ESR), and later
Any ONE of the following will mitigate the vulnerability:
- Upgrade to a fixed version of CiviCRM, or...
- Install the extension "Hotfix: Camel Attack", it can also be installed in-app from Administer > System Settings > Extensions, or...
- Apply this patch
Joseph LeDuc, Jamie McClelland of Progressive Technology Project, Coleman Watts and Tim Otten of CiviCRM Core Team, Seamus Lee of JMA Consulting
