PT-2023-31362 · Unknown · Uptime Kuma

Dj4Oc

+1

·

Published

2023-10-10

·

Updated

2023-12-14

·

CVE-2023-49804

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Uptime Kuma versions prior to 1.23.9
Description The issue allows unauthorized access to user accounts, compromising the security of sensitive information. When a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, even after system restarts or browser restarts. To mitigate the risks associated with this issue, the maintainers made the server emit a refresh event and then disconnecting all clients except the one initiating the password change.
Recommendations Update Uptime Kuma to version 1.23.9 or later. As a temporary workaround, consider restricting access to sensitive information until the update is applied.

Exploit

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2023-49804
GHSA-88J4-PCX8-Q4Q3
GHSA-G9V2-WQCJ-J99G

Affected Products

Uptime Kuma