PT-2024-21044 · Iris · Iris
Cyber-Dude1
·
Published
2024-04-25
·
Updated
2024-12-10
·
CVE-2024-25624
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Iris versions prior to 2.4.6
Description
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Due to an improper setup of the Jinja2 environment, reports generation in
iris-web is prone to a Server Side Template Injection (SSTI). Successful exploitation can lead to an arbitrary Remote Code Execution. An authenticated administrator must upload a crafted report template containing the payload. Upon generation of a report based on the weaponized report, any user can trigger the issue.Recommendations
Update to IRIS v2.4.6 as soon as possible. Until patching, review the report templates and keep the administrative privileges that include the upload of report templates limited to dedicated users.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Iris