Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49805

Опубликовано: 11 дек. 2023
Источник: nvd
CVSS3: 6
CVSS3: 8.8
EPSS Низкий

Описание

Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to access the application on behalf of their client. When connecting to the server using Socket.IO, the server does not validate the Origin header leading to other site being able to open connections to the server and communicate with it. Other websites still need to authenticate to access most features, however this can be used to circumvent firewall protections made in place by people deploying the application.

Without origin validation, Javascript executed from another origin would be allowed to connect to the application without any user interaction. Without login credentials, such a connection is unable to access protected endpoints containing sensitive data of the application. However, such a connection may allow attacker to further exploit unseen vu

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dockge.kuma:dockge:*:*:*:*:*:*:*:*
Версия до 1.3.3 (исключая)
cpe:2.3:a:uptime.kuma:uptime_kuma:*:*:*:*:*:*:*:*
Версия до 1.23.9 (исключая)

EPSS

Процентиль: 1%
0.00012
Низкий

6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-1385
CWE-346

EPSS

Процентиль: 1%
0.00012
Низкий

6 Medium

CVSS3

8.8 High

CVSS3

Дефекты

CWE-1385
CWE-346