CVE-2023-44400

Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3 has a patch for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:uptime.kuma:uptime_kuma:*:*:*:*:*:*:*:*

History

13 Oct 2023, 18:24

Type Values Removed Values Added
First Time Uptime.kuma
Uptime.kuma uptime Kuma
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References (MISC) https://github.com/louislam/uptime-kuma/issues/3481 - (MISC) https://github.com/louislam/uptime-kuma/issues/3481 - Issue Tracking, Mitigation
References (MISC) https://github.com/louislam/uptime-kuma/commit/88afab6571ef7d4d41bb395cdb6ecd3968835a4a - (MISC) https://github.com/louislam/uptime-kuma/commit/88afab6571ef7d4d41bb395cdb6ecd3968835a4a - Patch
References (MISC) https://github.com/louislam/uptime-kuma/security/advisories/GHSA-g9v2-wqcj-j99g - (MISC) https://github.com/louislam/uptime-kuma/security/advisories/GHSA-g9v2-wqcj-j99g - Exploit, Vendor Advisory
CPE cpe:2.3:a:uptime.kuma:uptime_kuma:*:*:*:*:*:*:*:*

09 Oct 2023, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-09 16:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-44400

Mitre link : CVE-2023-44400

CVE.ORG link : CVE-2023-44400


JSON object : View

Products Affected

uptime.kuma

  • uptime_kuma
CWE
CWE-384

Session Fixation