Description
The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do not sanitize user input in the filter selection menu, which may result in complete account takeover. It has been noted that the front-end uses `DOMPurify` or Vue templating to escape cross-site scripting (XSS) extensively, however certain areas of the front end lack this XSS protection. When combining the missing protection with the insecure authentication handling that the front-end uses, a malicious user may be able to take over any victim's account provided they meet the exploitation steps. As of time of publication, no patched version is available.
Published: 2024-07-25
Score: 8.8 High
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-39197 The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do not sanitize user input in the filter selection menu, which may result in complete account takeover. It has been noted that the front-end uses `DOMPurify` or Vue templating to escape cross-site scripting (XSS) extensively, however certain areas of the front end lack this XSS protection. When combining the missing protection with the insecure authentication handling that the front-end uses, a malicious user may be able to take over any victim's account provided they meet the exploitation steps. As of time of publication, no patched version is available.
History

Tue, 13 Aug 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Openobserve
Openobserve openobserve
CPEs cpe:2.3:a:openobserve:openobserve:*:*:*:*:*:*:*:*
Vendors & Products Openobserve
Openobserve openobserve

Subscriptions

Openobserve Openobserve
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T04:46:52.985Z

Reserved: 2024-07-22T13:57:37.135Z

Link: CVE-2024-41808

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:52.985Z

cve-icon NVD

Status : Modified

Published: 2024-07-25T20:15:05.153

Modified: 2024-11-21T09:33:06.860

Link: CVE-2024-41808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses