PT-2023-18527 · Unknown · Canarytokens

Azh-R

·

Published

2023-01-06

·

Updated

2023-01-12

·

CVE-2023-22475

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Canarytokens versions prior to sha-fb61290
Description A Cross-Site Scripting issue was identified in the history page of triggered Canarytokens. An attacker who discovers an HTTP-based Canarytoken can execute Javascript in the Canarytoken's trigger history page when the history page is later visited by the Canarytoken's creator. This could be used to disable or delete the affected Canarytoken, view its activation history, or reveal more information about the Canarytoken's creator, such as their email address. The attacker could also redirect the creator towards an attacker-controlled Canarytoken to show the creator's network location.
Recommendations For versions prior to sha-fb61290, update to Canarytokens Docker images sha-fb61290 or later, which contain a patch for this issue. As a temporary workaround, consider restricting access to the history page of triggered Canarytokens until the patch is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-22475
GHSA-3H2C-3FGR-74VH
GHSA-5675-3424-HPQR

Affected Products

Canarytokens