PT-2024-28724 · Unknown+1 · Ruby On Rails+1
P-
·
Published
2024-07-19
·
Updated
2024-08-23
·
CVE-2024-39906
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Haven blog web application (affected versions not specified)
Description
A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, but an attacker can craft a link that they can pass to a logged in administrator of the blog software. This leads to the immediate execution of the provided commands when the link is accessed by the authenticated administrator. This issue may lead to Remote Code Execution (RCE).
Recommendations
To resolve the issue, users are advised to upgrade to a version that includes the fix commit
c52f07c.
As a temporary workaround, consider restricting access to the IndieAuth functionality until the issue is resolved.
There are no known workarounds for this vulnerability.Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Haven
Ruby On Rails