PT-2024-29493 · Unknown · Canarytokens

Francesco Lacerenza

+1

·

Published

2024-07-23

·

Updated

2024-07-24

·

CVE-2024-41664

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Canarytokens versions prior to sha-8ea5315
Description Canarytokens help track activity and actions on a network. The Webhook alert feature in Canarytokens.org was vulnerable to a blind Server-Side Request Forgery (SSRF) prior to sha-8ea5315. When a Canarytoken is created, users can choose to receive alerts via email or a webhook. If a webhook is supplied, the site makes a test request to the supplied URL to ensure it accepts alert notification HTTP requests. No safety checks were performed on the URL, leading to the SSRF vulnerability. The SSRF is blind because the content of the response is not displayed to the creating user; they are simply told whether an error occurred in making the test request. Using the Blind SSRF, it was possible to map out open ports for IPs inside the Canarytokens.org infrastructure.
Recommendations For self-hosted Canarytokens installations, update by pulling the latest Docker image, or any Docker image after sha-097d91a. As a temporary workaround, consider restricting the use of the Webhook alert feature until the issue is resolved. Avoid using the Webhook alert feature with untrusted URLs to minimize the risk of exploitation.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-41664
GHSA-G6H5-PF7P-QMVJ

Affected Products

Canarytokens