Description
changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use a reverse shell. The impact is critical as the attacker can completely takeover the server machine. This can be reduced if changedetection is behind a login page, but this isn't required by the application (not by default and not enforced).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4r7v-whpg-8rx3 | changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:52:14.004Z
Reserved: 2024-04-16T14:15:26.876Z
Link: CVE-2024-32651
Updated: 2024-08-02T02:13:40.303Z
Status : Awaiting Analysis
Published: 2024-04-26T00:15:08.550
Modified: 2024-11-21T09:15:23.947
Link: CVE-2024-32651
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA