PT-2024-33493 · Umbrel · Umbrel

P-

+1

·

Published

2024-11-08

·

Updated

2024-11-15

·

CVE-2024-49379

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Umbrel versions prior to 1.2.2
Description The login functionality of Umbrel contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can specify a malicious redirect query parameter to trigger the vulnerability. If a JavaScript URL is passed to the redirect parameter, the attacker-provided JavaScript will be executed after the user enters their password and clicks on login.
Recommendations For versions prior to 1.2.2, update to version 1.2.2 or later to resolve the issue. As a temporary workaround, consider disabling the login functionality until a patch is available. Restrict access to the use-auth.tsx module to minimize the risk of exploitation. Avoid using the redirect parameter in the login functionality until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-49379

Affected Products

Umbrel