PT-2024-36794 · Unknown · Uptime Kuma
Griisemine
·
Published
2024-12-20
·
Updated
2024-12-20
·
CVE-2024-56331
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Uptime Kuma versions prior to 1.23.16
Description
An Improper URL Handling issue allows an attacker to access sensitive local files on the server by exploiting the
file:/// protocol. This issue is triggered via the "real-browser" request type, which takes a screenshot of the URL provided by the attacker. By supplying local file paths, such as file:///etc/passwd, an attacker can read sensitive data from the server. The system does not properly validate or sanitize the user input for the URL field, allowing users to input arbitrary file paths without server-side validation. Any authenticated user who can submit a URL in "real-browser" mode is at risk of exposing sensitive data through screenshots of these files.Recommendations
For versions prior to 1.23.16, upgrade to version 1.23.16 or later to address this issue. As a temporary workaround, consider restricting access to the "real-browser" request type to minimize the risk of exploitation. Additionally, restrict access to sensitive files on the server to prevent potential data exposure.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uptime Kuma