Executive brief
Uptime Kuma is an open-source monitoring platform that tracks the uptime and status of services and websites. This vulnerability allows previously logged-in users to maintain full read-write access to the platform even after the account password is changed, as long as they don't explicitly log out. An attacker with temporary access to a user's device could gain permanent unauthorized access to the monitoring system and sensitive operational data.
Technical details
The vulnerability is a session management flaw (CWE-384: Session Fixation) in Uptime Kuma's authentication system. When a user changes their password, the platform fails to invalidate all existing authenticated socket connections and JWT tokens for that user. This allows previously authenticated clients to retain full access without re-authentication, even across system restarts and browser cache clears. The attack requires local or adjacent access to a device where the user was previously authenticated, or compromised credentials on an existing session. The fix, released in version 1.23.9, makes the server emit a refresh event and disconnect all clients except the one initiating the password change.
Affected products
- Louis Lam Uptime Kuma before 1.23.9
Timeline
- 2023-12-07: disclosed: Vulnerability reported in public issue tracker (against security policy)
- 2023-12-10: patched: Uptime Kuma released patch version 1.23.9
- 2023-12-10: advisory: GHSA-88j4-pcx8-q4q3 and CVE-2023-49804 published