PT-2024-29899 · Homepage · Homepage

Kevin Stubbings

+1

·

Published

2024-08-23

·

Updated

2024-09-12

·

CVE-2024-42364

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Homepage version 0.9.1
Description The default setup of Homepage is vulnerable to DNS rebinding due to the lack of certificate and authentication. An attacker can exploit this by changing the DNS records of their domain to the internal IP address of the Homepage instance, allowing them to extract private information such as API keys and other sensitive data. The attack involves the attacker's website changing its DNS records to the internal IP address of the Homepage instance, and then fetching the attacker's domain, which responds with the Homepage instance's data.
Recommendations For version 0.9.1, update to a newer version as soon as it becomes available, as the current version is vulnerable to DNS rebinding. As a temporary workaround, consider setting up certificate and authentication for the Homepage instance to prevent DNS rebinding attacks. Restrict access to the Homepage instance to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2024-42364

Affected Products

Homepage