OneUptime is a solution for monitoring and managing online services. The vulnerability lies in the improper validation of client-side stored data within the web application. Specifically, the is_master_admin key, stored in the local storage of the browser, can be manipulated by an attacker. By changing this key from false to true, the application grants administrative privileges to the user, without proper server-side validation. This has been patched in 7.0.1815.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-03-24T19:04:53.789Z

Updated: 2024-03-24T19:04:53.789Z

Reserved: 2024-03-18T17:07:00.095Z


Link: CVE-2024-29194

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-03-24T19:15:07.240

Modified: 2024-03-25T01:51:01.223


Link: CVE-2024-29194

JSON object: View

cve-icon Redhat Information

No data.

CWE