CVE-2024-42364
Last modified
CVE-2024-42364 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Homepage is a highly customizable homepage with Docker and service API integrations. The default setup of homepage 0.9.1 is vulnerable to DNS rebinding. Homepage is setup without certificate and authentication by default, leaving it to vulnerable to DNS rebinding. In this attack, an attacker will ask a user to visit his/her website. The attacker website will then change the DNS records of their domain from their IP address to the internal IP address of the homepage instance. To tell which IP addresses are valid, we can rebind a subdomain to each IP address we want to check, and see if there is a response. Once potential candidates have been found, the attacker can launch the attack by reading the response of the webserver after the IP address has changed. When the attacker domain is fetched, the response will be from the homepage instance, not the attacker website, because the IP address has been changed. Due to a lack of authentication, a user’s private information such as API keys (fixed after first report) and other private information can then be extracted by the attacker website.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gethomepage | Homepage | 0.9.1 |
References
- https://securitylab.github.com/advisories/GHSL-2024-096_homepage/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-42364?
How severe is CVE-2024-42364?
How do I fix CVE-2024-42364?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-42358PDFio is a simple C library for reading and writing PDF file…5.5
- CVE-2024-4236A vulnerability, which was classified as critical, has been …8.8
- CVE-2024-42360SequenceServer lets you rapidly set up a BLAST+ server with …9.8
- CVE-2024-42361Hertzbeat is an open source, real-time monitoring system. He…9.8
- CVE-2024-42362Hertzbeat is an open source, real-time monitoring system. He…8.8
- CVE-2024-42363Prior to 3385, the user-controlled role parameter enters the…8.8
- CVE-2024-42365Asterisk is an open source private branch exchange (PBX) and…8.8
- CVE-2024-42366VRCX is an assistant/companion application for VRChat. In ve…9
- CVE-2024-42367aiohttp is an asynchronous HTTP client/server framework for …4.8
- CVE-2024-42368OpenTelemetry, also known as OTel, is a vendor-neutral open …6.5
- CVE-2024-42369matrix-js-sdk is a Matrix messaging protocol Client-Server S…5.3
- CVE-2024-4237A vulnerability, which was classified as critical, was found…8.8
Are you affected by CVE-2024-42364?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
