The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform through 0.9.1 do not sanitize user input in the filter selection menu, which may result in complete account takeover. It has been noted that the front-end uses `DOMPurify` or Vue templating to escape cross-site scripting (XSS) extensively, however certain areas of the front end lack this XSS protection. When combining the missing protection with the insecure authentication handling that the front-end uses, a malicious user may be able to take over any victim's account provided they meet the exploitation steps. As of time of publication, no patched version is available.
History

Tue, 13 Aug 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Openobserve
Openobserve openobserve
CPEs cpe:2.3:a:openobserve:openobserve:*:*:*:*:*:*:*:*
Vendors & Products Openobserve
Openobserve openobserve

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-07-25T20:10:04.248Z

Updated: 2024-08-02T04:46:52.985Z

Reserved: 2024-07-22T13:57:37.135Z

Link: CVE-2024-41808

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:52.985Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-25T20:15:05.153

Modified: 2024-08-13T13:40:02.497

Link: CVE-2024-41808

cve-icon Redhat

No data.