Junglewise Threat Intelligence

CVE-2024-29194: OneUptime privilege escalation via local storage manipulation

CVE-2024-29194 · Severity: low · CVSS 3.1 · Published 2024-03-25

Technologies: OneUptime. Vendors: OneUptime, npm.

Executive brief

OneUptime, an open-source monitoring and observability platform, is vulnerable to a flaw that allows standard users to gain administrative access. By simply modifying a value in their browser's local storage, an authenticated user can trick the system into granting them elevated permissions. This could allow unauthorized individuals to view sensitive information, such as the full list of registered users on the platform.

Technical details

A privilege escalation vulnerability exists in OneUptime due to improper server-side validation of authorization flags stored in the browser's local storage. Specifically, the application relies on the 'is_master_admin' key within local storage to determine administrative status. An authenticated attacker can use browser developer tools to manually change this key from 'false' to 'true'. Because the backend fails to verify this status against its own records, the attacker gains access to administrative functionalities, including the ability to view the complete list of registered users. The issue is addressed in version 7.0.1815 by implementing proper server-side checks.

Affected products

  • OneUptime OneUptime >= 7.0.1803, < 7.0.1815

Timeline

  • 2024-03-22: patched: Fix committed to repository
  • 2024-03-24: disclosed: NVD and GitHub Advisory published

References

Related threats