Indian Digilocker Accounts could have been easily accessed by threat attackers due to Vulnerability

Continue reading
The Government of India has found a critical weakness in its secure document wallet service Digilocker, which could have allowed a threat attacker to bypass mobile one-time passwords (OTPs) and sign in as other users.
Two Independent bug bounty researchers, Ashish Gahlot and Mohesh Mohan discovered the vulnerability which could have let the attacker gain access to sensitive documents uploaded by the victim on Digilocker.
"The OTP feature requires permission to perform OTP validation by sending some legitimate user information and then manipulating the flow to log in as a completely different user," said Mohesh Mohan.
With more than 38 million registered users, Digilocker is a cloud-based repository that acts as a digital platform for facilitating the online processing of documents and faster delivery of various government-to-citizen services. A unique identity number (UID) is issued to the user that is linked to their mobile number and Aadhar ID.
According to Mohan, all the attacker needs to know is either a victim's Aadhaar ID or a linked mobile number or username for unauthorized access to the targeted Digilocker account, prompting the service to send an OTP, and then exploiting the failure to bypass the sign-in method.
The Digilocker Mobile App version also comes with a 4-digit PIN for an added layer of protection. However, the researchers said that it was possible to modify the API calls to authenticate the PIN by associating the PIN to another user (identified with version-5 UUID) and successfully login as a victim.
The intruder could have done the SMS OTP [verification] as a single user and sent a second user pin and eventually ended up logging in as a second user.
The lack of authorization for the endpoint of the API used to set the secret PIN effectively implies that the API can be used to reset the PIN linked to a random user using the individual UUID.

In addition to the issues listed above, API calls from mobile apps have been protected by simple authentication that can be circumvented by removing the "is encrypted:1" header flag. The application has also been found to enforce a poor SSL pinning mechanism, rendering them susceptible to bypass using tools like Frida.
On May 28, the issue was fixed by the cyber agency, followed by a statement on Twitter acknowledging the flaw.
"This vulnerability was discovered to have been cracked in the code when some new features were added recently. The vulnerability has been resolved on a priority basis by the technical team within the day of receipt of the CERT-In alert. No type of data was compromised, this was not an infrastructure attack." the agency ensured.

A publicly accessible registration portal, a misconfigured Entra tenant, and no server-side authorization checks. That was enough to reach the systems controlling live World Cup streams