PT-2024-29899 · Homepage · Homepage
Kevin Stubbings
+1
·
Published
2024-08-23
·
Updated
2024-09-12
·
CVE-2024-42364
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Homepage version 0.9.1
Description
The default setup of Homepage is vulnerable to DNS rebinding due to the lack of certificate and authentication. An attacker can exploit this by changing the DNS records of their domain to the internal IP address of the Homepage instance, allowing them to extract private information such as API keys and other sensitive data. The attack involves the attacker's website changing its DNS records to the internal IP address of the Homepage instance, and then fetching the attacker's domain, which responds with the Homepage instance's data.
Recommendations
For version 0.9.1, update to a newer version as soon as it becomes available, as the current version is vulnerable to DNS rebinding.
As a temporary workaround, consider setting up certificate and authentication for the Homepage instance to prevent DNS rebinding attacks.
Restrict access to the Homepage instance to minimize the risk of exploitation until a patch is available.
Exploit
Fix
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Homepage