PT-2024-29492 · Unknown · Canarytokens

Francesco Lacerenza

+1

·

Published

2024-07-23

·

Updated

2024-07-24

·

CVE-2024-41663

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Canarytokens versions prior to the latest Docker image (after sha-097d91a)
Description A Cross-Site Scripting issue was identified in the "Cloned Website" Canarytoken. The creator of a slow-redirect Canarytoken can insert Javascript into the destination URL of their slow redirect token. When the creator later browses the management page for their own Canarytoken, the Javascript executes, resulting in a self-XSS. An attacker could create a Canarytoken with this self-XSS and send the management link to a victim, allowing the Javascript to execute when they click on it. However, no sensitive information, such as session information, will be disclosed to the malicious actor.
Recommendations For self-hosted Canarytokens installations, update by pulling the latest Docker image, or any Docker image after sha-097d91a. As a temporary workaround, consider restricting access to the management page of the Canarytoken until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41663
GHSA-XJ9H-3J9C-C95H

Affected Products

Canarytokens