PT-2024-4060 · Unknown · Irisevtxmodule

Cyber-Dude1

·

Published

2024-02-04

·

Updated

2024-05-24

·

CVE-2024-34060

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: IrisEVTXModule versions prior to 1.0.0
Description: The issue is related to the incorrect restriction of the directory path name with limited access in the IrisEVTXModule, which handles Microsoft EVTX log files. This can lead to remote code execution (RCE) when combined with a Server Side Template Injection (SSTI) due to the unsafe handling of filenames during EVTX file upload.
Recommendations: For versions prior to 1.0.0, update to version 1.0.0 to resolve the issue. As a temporary workaround, consider restricting access to the iris-evtx-module pipeline plugin to minimize the risk of exploitation. Avoid using the vulnerable iris-evtx-module until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-04505
CVE-2024-34060
GHSA-9RW6-5Q9J-82FM

Affected Products

Irisevtxmodule