Vulnerability Description
OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_master_admin key, stored in the local storage of the browser, can be manipulated by an attacker. By changing this key from false to true, the application grants administrative privileges to the user, without proper server-side validation. This has been patched in 7.0.1815.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hackerbay | Oneuptime | >= 7.0.1803, < 7.0.1815 |
Related Weaknesses (CWE)
References
- https://github.com/OneUptime/oneuptime/commit/14016d23d834038dd65d3a96cf71af04b5Patch
- https://github.com/OneUptime/oneuptime/security/advisories/GHSA-246p-xmg8-wmcqExploitRelease Notes
- https://github.com/OneUptime/oneuptime/commit/14016d23d834038dd65d3a96cf71af04b5Patch
- https://github.com/OneUptime/oneuptime/security/advisories/GHSA-246p-xmg8-wmcqExploitRelease Notes
FAQ
What is CVE-2024-29194?
CVE-2024-29194 is a vulnerability with a CVSS score of 8.3 (HIGH). OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_maste...
How severe is CVE-2024-29194?
CVE-2024-29194 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29194?
Check the references section above for vendor advisories and patch information. Affected products include: Hackerbay Oneuptime.