Executive brief
OneUptime is an open-source monitoring and observability platform that enables account password resets. The application logs the complete password reset URL—containing a plaintext reset token—at the INFO level by default in production. This means any person with access to logs (whether in Docker, Kubernetes, log aggregation systems like Elasticsearch or Datadog, or shared log volumes) can extract these tokens and take over any user account in the system.
Technical details
The vulnerability is a sensitive information disclosure (CWE-532) in the password reset flow. The vulnerable code in App/FeatureSet/Identity/API/Authentication.ts (lines 370-371) logs the complete password reset URL containing the plaintext token via logger.info(). This log level is enabled by default in production and persists to stdout, log files, and any configured log aggregation systems. The attack requires only read access to application logs—no authentication or network traversal is needed beyond accessing the logging infrastructure. An attacker can extract the plaintext token, then call the reset-password API endpoint with the stolen token to reset the victim's password. Additionally, login credentials (including cleartext passwords) are logged at DEBUG level (line 909), which is commonly enabled during incident troubleshooting. The vulnerability affects all versions of OneUptime up to and including 10.0.23 and is patched in 10.0.24.
Affected products
- OneUptime oneuptime all versions up to 10.0.23
Timeline
- 2026-03-13: disclosed: Advisory published
- 2026-03-13: patched: Fixed in version 10.0.24