CVE-2024-32651

changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).
Configurations

No configuration.

History

21 Nov 2024, 09:15

Type Values Removed Values Added
References () https://blog.hacktivesecurity.com/index.php/2024/05/08/cve-2024-32651-server-side-template-injection-changedetection-io/ - () https://blog.hacktivesecurity.com/index.php/2024/05/08/cve-2024-32651-server-side-template-injection-changedetection-io/ -
References () https://github.com/dgtlmoon/changedetection.io/releases/tag/0.45.21 - () https://github.com/dgtlmoon/changedetection.io/releases/tag/0.45.21 -
References () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-4r7v-whpg-8rx3 - () https://github.com/dgtlmoon/changedetection.io/security/advisories/GHSA-4r7v-whpg-8rx3 -
References () https://www.onsecurity.io/blog/server-side-template-injection-with-jinja2 - () https://www.onsecurity.io/blog/server-side-template-injection-with-jinja2 -

07 Jun 2024, 17:15

Type Values Removed Values Added
References
  • () https://blog.hacktivesecurity.com/index.php/2024/05/08/cve-2024-32651-server-side-template-injection-changedetection-io/ -
Summary
  • (es) changetection.io es un servicio de detección de cambios de páginas web, seguimiento de sitios web, monitor de reabastecimiento y notificación de código abierto. Hay una inyección de plantilla del lado del servidor (SSTI) en Jinja2 que permite la ejecución remota de comandos en el host del servidor. Los atacantes pueden ejecutar cualquier comando del sistema sin ninguna restricción y podrían usar un shell inverso. El impacto es crítico ya que el atacante puede apoderarse completamente de la máquina servidor. Esto se puede reducir si la detección de cambios está detrás de una página de inicio de sesión, pero la aplicación no lo requiere (no es de forma predeterminada ni obligatorio).

26 Apr 2024, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-26 00:15

Updated : 2024-11-21 09:15


NVD link : CVE-2024-32651

Mitre link : CVE-2024-32651

CVE.ORG link : CVE-2024-32651


JSON object : View

Products Affected

No product.

CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine