PT-2024-28724 · Unknown+1 · Ruby On Rails+1

P-

·

Published

2024-07-19

·

Updated

2024-08-23

·

CVE-2024-39906

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Haven blog web application (affected versions not specified)
Description A command injection vulnerability was found in the IndieAuth functionality of the Ruby on Rails based Haven blog web application. The affected functionality requires authentication, but an attacker can craft a link that they can pass to a logged in administrator of the blog software. This leads to the immediate execution of the provided commands when the link is accessed by the authenticated administrator. This issue may lead to Remote Code Execution (RCE).
Recommendations To resolve the issue, users are advised to upgrade to a version that includes the fix commit c52f07c. As a temporary workaround, consider restricting access to the IndieAuth functionality until the issue is resolved. There are no known workarounds for this vulnerability.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2024-39906
GHSA-65CM-7G24-HM9F

Affected Products

Haven
Ruby On Rails