PT-2023-18527 · Unknown · Canarytokens
Azh-R
·
Publicado
2023-01-06
·
Atualizado
2023-01-12
·
CVE-2023-22475
CVSS v3.1
6.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Canarytokens versions prior to sha-fb61290
Description
A Cross-Site Scripting issue was identified in the history page of triggered Canarytokens. An attacker who discovers an HTTP-based Canarytoken can execute Javascript in the Canarytoken's trigger history page when the history page is later visited by the Canarytoken's creator. This could be used to disable or delete the affected Canarytoken, view its activation history, or reveal more information about the Canarytoken's creator, such as their email address. The attacker could also redirect the creator towards an attacker-controlled Canarytoken to show the creator's network location.
Recommendations
For versions prior to sha-fb61290, update to Canarytokens Docker images sha-fb61290 or later, which contain a patch for this issue. As a temporary workaround, consider restricting access to the history page of triggered Canarytokens until the patch is applied.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Canarytokens