CVE-2024-32651
Server Side Template Injection in Jinja2 allows Remote Command Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).
changetection.io es un servicio de detección de cambios de páginas web, seguimiento de sitios web, monitor de reabastecimiento y notificación de código abierto. Hay una inyección de plantilla del lado del servidor (SSTI) en Jinja2 que permite la ejecución remota de comandos en el host del servidor. Los atacantes pueden ejecutar cualquier comando del sistema sin ninguna restricción y podrían usar un shell inverso. El impacto es crítico ya que el atacante puede apoderarse completamente de la máquina servidor. Esto se puede reducir si la detección de cambios está detrás de una página de inicio de sesión, pero la aplicación no lo requiere (no es de forma predeterminada ni obligatorio).
changedetection versions 0.45.20 and below suffer from a remote code execution vulnerability.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-04-16 CVE Reserved
- 2024-04-25 CVE Published
- 2024-05-26 First Exploit
- 2024-06-08 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
CAPEC
References (6)
URL | Date | SRC |
---|---|---|
https://github.com/zcrosman/cve-2024-32651 | 2024-05-26 | |
https://github.com/s0ck3t-s3c/CVE-2024-32651-changedetection-RCE | 2024-09-18 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dgtlmoon Search vendor "Dgtlmoon" | Changedetection.io Search vendor "Dgtlmoon" for product "Changedetection.io" | <= 0.45.20 Search vendor "Dgtlmoon" for product "Changedetection.io" and version " <= 0.45.20" | en |
Affected
|