CVE-2024-3164
Last modified
CVE-2024-3164 is a medium-severity vulnerability rated 4.5/10 on the CVSS scale. In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet. This would share database username and password under Log Files and download DB Dump and other dotCMS Content under Tools. Nothing in the System → Maintenance should be displayed for users with site admin role. Only system admins must have access to System Maintenance. OWASP Top 10 - A01) Broken Access Control OWASP Top 10 - A04) Insecure Design
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Dotcms | Dotcms | >= 22.02, < 22.03.15 | — |
| Dotcms | Dotcms | >= 23.01, < 23.01.15 | — |
| Dotcms | Dotcms | >= 23.02, <= 23.09.7 | — |
| Dotcms | Dotcms | 23.10.24 | 1 |
References
- https://github.com/dotCMS/core/issues/27909Issue Tracking
- https://github.com/dotCMS/core/pull/27912Issue Tracking
- https://www.dotcms.com/security/SI-69Broken Link
- https://github.com/dotCMS/core/issues/27909Issue Tracking
- https://github.com/dotCMS/core/pull/27912Issue Tracking
- https://www.dotcms.com/security/SI-69Broken Link
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-3164?
How severe is CVE-2024-3164?
How do I fix CVE-2024-3164?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-31629Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-3163The Easy Property Listings WordPress plugin before 3.5.4 doe…4.3
- CVE-2024-31630Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-31631Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-31634Cross Site Scripting (XSS) vulnerability in Xunruicms versio…6.1
- CVE-2024-31636An issue in LIEF v.0.14.1 allows a local attacker to obtain …3.9
- CVE-2024-31648Cross Site Scripting (XSS) in Insurance Management System v1…6.1
- CVE-2024-31649A cross-site scripting (XSS) in Cosmetics and Beauty Product…5.4
- CVE-2024-3165System->Maintenance-> Log Files in dotCMS dashboard is provi…4.5
- CVE-2024-31650A cross-site scripting (XSS) in Cosmetics and Beauty Product…9.6
- CVE-2024-31651A cross-site scripting (XSS) in Cosmetics and Beauty Product…6.1
- CVE-2024-31652A cross-site scripting (XSS) in Cosmetics and Beauty Product…6.1
Are you affected by CVE-2024-3164?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
