PT-2021-22430 · Cachet · Cachet

Thomas Chauchefoin

·

Published

2021-08-27

·

Updated

2022-12-13

·

CVE-2021-39172

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cachet versions prior to 2.5.1
Description Cachet is an open source status page system. Authenticated users, regardless of their privileges, can exploit a new line injection in the configuration edition feature and gain arbitrary code execution on the server. This issue was addressed by improving UpdateConfigCommandHandler and preventing the use of new lines characters in new configuration values.
Recommendations For versions prior to 2.5.1, update to version 2.5.1 to resolve the issue. As a temporary workaround, only allow trusted source IP addresses to access the administration dashboard.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-39172
GHSA-9JXW-CFRH-JXQ6

Affected Products

Cachet