CVE-2023-36821

CVSS Score of 10 (low)

Details

Published Jul 5, 2023
Updated: Jul 12, 2023
CWE ID 20

Summary

CVE-2023-36821: Uptime Kuma, a self-hosted monitoring tool prior to version 1.22.1, has a vulnerability that allows an authenticated attacker to install a maliciously crafted plugin, potentially leading to remote code execution. The vulnerability arises from the ability of authenticated users to install plugins from an official list using the web interface's disabled feature but still accessible API endpoints. By downloading and installing a plugin without validation or ignoring scripts, a maliciously crafted plugin can exploit npm scripts and execute remote code. Organizations using affected versions of Uptime Kuma should update to version 1.22.1 to mitigate this risk of unauthorized code execution. The severity of this vulnerability is rated as high (CVSS score: 8.8) due to its potential impact on confidentiality, integrity, and availability of the system.

Leverage our Vulnerability Intelligence module to secure your systems now - get detailed insights on CVE-2024-37364. Book your demo today.

Share

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2023-36821 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options