Improper URL Handling in Uptime Kuma Monitoring Tool
CVE-2024-56331
What is CVE-2024-56331?
CVE-2024-56331 identifies a critical improper URL handling vulnerability in the Uptime Kuma monitoring tool. This flaw enables an authenticated attacker to leverage the 'real-browser' request functionality to access sensitive local files on the server by exploiting the 'file://' protocol. The vulnerability arises from the lack of input validation and sanitization for the user-provided URL input. When an attacker inputs a local file path, such as 'file:///etc/passwd', the system fails to prevent unauthorized file access, allowing attackers to capture screenshots of confidential file contents. Users are strongly urged to upgrade to version 1.23.16 or later, as there are no viable workarounds available to mitigate this security risk.
Affected Version(s)
uptime-kuma >= 1.23.0, < 1.23.16 < 1.23.0, 1.23.16
uptime-kuma = 2.0.0-beta.0 = 2.0.0-beta.0
