PT-2024-21044 · Iris · Iris

Cyber-Dude1

·

Published

2024-04-25

·

Updated

2024-12-10

·

CVE-2024-25624

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Iris versions prior to 2.4.6
Description Iris is a web collaborative platform that helps incident responders share technical details during investigations. Due to an improper setup of the Jinja2 environment, reports generation in iris-web is prone to a Server Side Template Injection (SSTI). Successful exploitation can lead to an arbitrary Remote Code Execution. An authenticated administrator must upload a crafted report template containing the payload. Upon generation of a report based on the weaponized report, any user can trigger the issue.
Recommendations Update to IRIS v2.4.6 as soon as possible. Until patching, review the report templates and keep the administrative privileges that include the upload of report templates limited to dedicated users.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-25624
GHSA-M64W-F7FG-HPCR

Affected Products

Iris