Third Party Index

Snapshot 20962

Document
Security page
URL
https://security.revizto.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
132874 bytes
SHA-256 (raw)
f8092cc73ef5d06cd2278a1b248848aeedb0266575b9dd5a2ef0c413f27d4a92
SHA-256 (normalized text)
323be3a3faac666f0408f763cc8acd5a9480f05e3bcf79b9672c77ececaad96f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Revizto
[email protected]
Privacy PolicyOpens in new tab
Revizto is the leading Integrated Collaboration Platform for the Architecture, Engineering, Construction & Operations (AECO) industry, transforming the way we design and build by driving efficiency, reducing errors, and simplifying complexity. From real-time coordination to automated clash detection and issue tracking, Revizto keeps all stakeholders aligned throughout the entire project lifecycle.
Backed by Summit Partners, Revizto is relied on by firms around the world like Jacobs, AECOM, AtkinsRealis, McCarthy, Skanska, Stantec, and others to deliver projects with greater confidence and control.
Compliance
ISO 27001:2022
ISO 27017
SOC 2 Type2
CSA star level 1
UK Cyber Essentials
U
UK Secure by Design
Resources
View all
Certificates
ISO/IEC 27001:2022 Statement of ApplicabilityOpens in new tab
Cyber Essentials certificate
Opens in new tab
Reports
SOC2 Type2 report (2024)
ISO/IEC 27001:2022, & 27017:2015 1st Surveillance Audit Report
Pentest Report Workspace 2025
View 4 more
Policy
Access Control Policy
Cryptography Policy
View 17 more
Other
Shared responsibility matrixOpens in new tab
Business Continuity and Disaster Recovery Plan
Incident Response Plan
Company StructureOpens in new tab
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 16 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Production inventory maintained
Portable media encrypted
View 11 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 1 more Product security control
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Configuration management system established
View 30 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Data collected
Customer personally identifiable information
Employee personally identifiable information
Customer project data
Credit card information
Personal health information
Subprocessors
View all
AWS
•
Main Cloud hosting
Switzerland, UK, Ireland, USA, Australia, Canada, Brazil, Singapore, Japan, United Arab Emirates
Data Type: Full user data
AliCloud
•
Separate Cloud hosting
China, Kingdom of Saudi Arabia
Data Type: Full user data
Mailgun
•
Email delivery
EU/US
Data Type: Emails
Amplitude
•
Analytics
EU/US
Data Type: Pseudonymized IDs
FAQ
View all
Updates
View all
Security
RVZ-SA-2026-002 - SAML Cross-Account Authentication Bypass in Revizto SSO
Published May 14, 2026
Security Advisory — RVZ-SA-2026-002
SAML Cross-Account Authentication Bypass in Revizto SSO (SP-initiated flow)
Field	Value
Revizto Vulnerability Advisory ID	RVZ-SA-2026-002
Severity (CVSS 3.1 Base)	8.2 — High
CVSS vector	CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Affected product / component	Revizto web platform — authentication service, SAML SP-initiated login flow
Impacted versions	All backend deployments prior to WEB-17260 (github.com/revizto/core PR #3038)
Mitigated versions	All production regions running post-WEB-17260 backend, deployed by [DD-Mon-2026 — to be filled by Infrastructure]
Date published	13-May-2026
Last updated	13-May-2026
Summary
During an internal security review, the Revizto Application Security team identified and fixed a flaw in the way Revizto handled Single Sign-On (SSO) logins. Under specific conditions, the flaw could have allowed someone with an active Revizto subscription, who also controlled an Identity Provider, to sign in as a different user — even one protected by two-factor authentication — and view or change parts of that user's profile. Revizto is not aware of any exploitation of this vulnerability.
The fix is deployed on Revizto's servers across all twelve production regions worldwide. No action is required from customers or end users. Revizto found no evidence that this issue was used to access any account, and is publishing this advisory to keep customers informed in line with its security commitments.
Description
What happened
When a customer uses Single Sign-On (SSO) to log into Revizto, the customer's Identity Provider (the corporate login service, for example Okta, Microsoft Entra ID, or a similar product) sends Revizto a digitally-signed message that says, in effect, "this person has been authenticated, you can let them in."
Revizto correctly checked that the message itself was valid. However, when Revizto then looked up the user account to log in, it searched across the whole region by email address — without confirming that the user belonged to the same customer organisation whose SSO setup had produced the message. In a narrow set of conditions, that gap could have allowed someone who controlled their own Identity Provider, and who knew a user's email address, to start a Revizto session as that other user. Because the session was created through SSO, two-factor authentication would not get a chance to challenge the attempt.
Once such a session was established, account-scoped business data (projects, issues, models) was still protected by a separate check and was not exposed. However, a smaller set of user-level actions — viewing the user's personal details, editing their profile, or disconnecting their third-party Common Data Environment (CDE) integrations — remained reachable until the fix was deployed.
Technical Detail (for security teams)
After SAML assertion validation, the authentication service performed a region-wide email lookup of the user without enforcing that the resolved user belonged to the account that owned the SAML authentication method. The post-login spEntityId check correctly blocked account-scoped business data, but user-level endpoints that did not depend on MemberLogic remained accessible to the cross-account session. The SAML flow bypassed two-factor authentication. The configuration wantAssertionsSigned: false reduced the cost of forging assertions where the target Identity Provider did not require them to be signed.
Potential Impact
If exploited, this vulnerability could result in gaining access to:
A user's personal information (first name, last name, email, organization memberships, project names).
Modifying the user's profile attributes.
Removing the user's OAuth integration connections to third-party Common Data Environments (CDEs).
Obtaining a password reset token.
Note: OAuth access tokens for third-party Common Data Environment (CDE) integrations are stored on the Revizto desktop client and are not retrievable through the affected web session.
Detection and Exploitation
Known Exploitation
Revizto is not aware of any exploitation of this vulnerability. The issue was identified through Revizto's internal threat-modelling programme and confirmed by the in-house Application Security team. A security verification was performed: at the present time, no users in the Revizto database have access to a third-party CDE outside of their own company, and no inbound report, public PoC, or third-party advisory indicates that there has been any past exploitation of the vulnerability.
Detection Guidance
No customer/user detection action is required. Customers wishing to review specific historical activity may contact Revizto Support for assisted review.
Mitigation and Remediation
Immediate Action
No customer/user action is required. Revizto has deployed a server-side fix, which is effective for all customers.
Permanent Fix
The authentication service now enforces an end-to-end binding between the email submitted at SSO initiation and the identity resolved from the SAML assertion. Cross-account session establishment is no longer possible through this code path.
The fix has been deployed to all twelve (12) Revizto-managed production regions: USA (Virginia), Canada (Quebec), Ireland (Dublin), United Kingdom (London), Switzerland (Zurich), United Arab Emirates (Abu Dhabi), Singapore (Singapore), Japan (Tokyo), Australia (Sydney), Brazil (São Paulo), China (Shanghai), and Kingdom of Saudi Arabia (Riyadh).
Deployment completed: 13-05-2026
Recommendations
As a matter of general best practice, we recommend Revizto customers reconnect their CDEs into Revizto, which will refresh the OAuth token.
References
Internal references: INFOSEC-1516, WEB-18584, WEB-17260
CVSS 3.1 vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
No corresponding public CVE has been assigned; the vulnerability is internal to the Revizto Solution.
Contact Information
For questions regarding this advisory, please contact the Security Team at [email protected].
For technical assistance with your tenant, please contact [email protected].
Security
RVZ-SA-2026-001: Important Information on Axios npm Supply Chain Compromise (plain-crypto-js RAT)
Published April 1, 2026
Related to Revizto Vulnerability Advisory ID: N/A — No advisory issued (Revizto not impacted)
Severity: CVSS Score 9.8 (Critical) — Impact: Remote Code Execution via supply chain compromise
Affected Product/Service/Component: npm packages [email protected], [email protected], [email protected] (third-party open-source)
Impacted Versions: axios 1.14.1, axios 0.30.4
Mitigated Versions: axios 1.14.0 and earlier; axios >=1.14.2 (once published by maintainers)
Date Published: 01-Apr-2026 Last Updated: 01-Apr-2026
SUMMARY
On 2026-03-31, a supply chain attack was identified targeting the widely used axios npm package. An attacker (attributed to UNC1069 / GOLDEN CHOLLIMA, a North Korea-linked threat actor) hijacked a maintainer account and published compromised versions 1.14.1 and 0.30.4. These versions include a postinstall script that installs [email protected], which drops a cross-platform Remote Access Trojan (RAT) targeting Linux, macOS, and Windows.
Revizto has conducted a thorough investigation and confirmed that the Revizto Solution, infrastructure, and endpoints are not affected by this vulnerability.
DESCRIPTION
The compromised axios versions execute a malicious postinstall script during npm install that downloads and installs [email protected]. This package deploys a cross-platform RAT capable of providing persistent remote access to the compromised host. The attack targets any development or production environment that resolved the affected axios versions via npm between 2026-03-31 and the time of package removal.
POTENTIAL IMPACT
No impact to Revizto. Our investigation confirmed:
No compromised packages were installed on any Revizto endpoint, build server, or production system.
No malicious process execution, file writes, or DNS activity associated with plain-crypto-js was detected across our fleet.
Proactive remediation was applied: all Revizto function apps that depend on axios have been pinned to the verified safe version 1.14.0 with exact version locks (removing range specifiers) to prevent automatic resolution to compromised versions.
DETECTION AND EXPLOITATION
Known Exploitation: Active exploitation in the wild via npm package resolution. The compromised versions have been reported to npm for removal.
Detection Guidance: Organizations should audit their node_modules directories and package-lock.json files for references to [email protected], [email protected], or plain-crypto-js. Endpoint detection logs should be reviewed for postinstall script execution spawning unexpected child processes from node.
Revizto's investigation included:
CrowdStrike Falcon NG-SIEM queries across all managed endpoints for process execution, file writes, and DNS activity matching the IOCs
Review of all npm postinstall activity on developer and build hosts between 2026-03-28 and 2026-04-01
Verification that no CrowdStrike detections or incidents are associated with these IOCs
Pinning of axios dependencies to known-safe versions across all five Azure Sentinel function apps
MITIGATION AND REMEDIATION
No action is required by Revizto customers. The Revizto Solution was not affected.
For awareness, the following defensive measures have been implemented internally:
All axios dependencies pinned to exact version 1.14.0 across function apps
Ongoing monitoring via CrowdStrike Falcon and LogScale for any IOCs related to this campaign
Continuous threat intelligence monitoring for related activity from GOLDEN CHOLLIMA / UNC1069
USER ADVICE
No action is required. This bulletin is published for transparency and to anticipate any queries from customers or partners regarding this widely reported supply chain attack. Revizto continues to monitor the situation and will publish updates if the threat landscape changes.
REFERENCES
npm advisory for axios (pending official CVE assignment)
CrowdStrike Intelligence: GOLDEN CHOLLIMA threat actor profile
Revizto internal investigation: CrowdStrike Falcon NG-SIEM hunt — 01-Apr-2026
CONTACT INFORMATION
For security-related questions about this bulletin, please contact our Security team at: [email protected]