Executive brief
Uptime Kuma is an open-source monitoring application that tracks the availability of websites and services. An attacker with local access to a user's device can permanently hijack the user's account by reusing session tokens that remain valid even after password changes or prolonged inactivity. This allows unauthorized access to sensitive monitoring data, API credentials, and the ability to modify or delete monitored services.
Technical details
The vulnerability stems from improper session management in Uptime Kuma's JWT token implementation (CWE-565, CWE-602, CWE-784). JWT tokens are stored in browser storage (sessionStorage or localStorage) and lack server-side validation after password changes or timeout periods. Specifically: (1) tokens have no expiration time and remain valid indefinitely, (2) password changes do not invalidate previously issued tokens on the server side, and (3) session tokens are only deleted client-side on logout, making them reusable by local attackers. The attack requires local device access (AV:Local, PR:High privilege level) and no user interaction. An attacker can gain persistent account access to view private monitors, access API keys and secrets, modify monitored endpoints, and exhaust system resources. The vulnerability is fixed in version 1.23.3 and later.
Affected products
- Louis Lam Uptime Kuma before 1.23.3
Timeline
- 2023-10-09: disclosed
- 2023-10-10: patched: fixed in version 1.23.3