CVE-2023-49804
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2023-49804 is a vulnerability affecting Uptime Kuma, a self-hosted monitoring tool. Before version 1.23.9, when a user changes their password, previously logged-in users retain access without being logged out. This inconsistency in authentication persists even after system or browser restarts, posing a significant risk to user accounts. Unauthorized individuals can gain access to sensitive information, compromising security. A previous patch (CVE-2023-44400) partially addressed this issue but failed to log users out, leaving the vulnerability unresolved. To mitigate risks, the maintainers implemented a `refresh` event and disconnected all clients except the one initiating the password change. It is strongly advised to update Uptime Kuma to version 1.23.9 to protect against unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.