PT-2024-19594 · Strangebee · Thehive
Published
2024-01-19
·
Updated
2025-06-09
·
CVE-2024-22876
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
StrangeBee TheHive versions 5.1.0 through 5.1.9
StrangeBee TheHive versions 5.2.0 through 5.2.8
Description
The issue concerns a Cross Site Scripting (XSS) vulnerability in the case attachment functionality. This allows an attacker to upload a malicious HTML file with Javascript code that will be executed in the context of the TheHive application using a specific URL. The vulnerability can be used to coerce a victim account to perform specific actions on the application, such as helping an analyst become an administrator.
Recommendations
For StrangeBee TheHive versions 5.1.0 through 5.1.9, consider disabling the case attachment functionality until a patch is available.
For StrangeBee TheHive versions 5.2.0 through 5.2.8, consider disabling the case attachment functionality until a patch is available.
As a temporary workaround, restrict access to the case attachment functionality to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thehive