PT-2024-39776 · Posthog · Posthog

Mdisec

+1

·

Published

2024-10-15

·

Updated

2025-01-03

·

CVE-2024-9710

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions PostHog (affected versions not specified)
Description This issue allows remote attackers to disclose sensitive information on affected installations of PostHog. Authentication is required to exploit this issue. The specific flaw exists within the implementation of the database schema method, resulting from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this issue to execute code in the context of the service account.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-9710
ZDI-24-1383

Affected Products

Posthog