CVE-2024-21645: pyLoad Log Injection
Summary A log injection vulnerability was identified in pyload. This vulnerability allows any unauthenticated actor to inject arbitrary messages into the logs gathered by pyload.
Details pyload will generate a log entry when attempting to sign in with faulty credentials. This entry will be in the form of Login failed for user 'USERNAME'. However, when supplied with a username containing a newline, this newline is not properly escaped. Newlines are also the delimiter between log entries. This allows the attacker to inject new log entries into the log file.
PoC Run pyload in the default configuration by running the following command pyload
We can now sign in as the pyload user and view the logs at http://localhost:8000/logs. !Viewing the logs
Any unauthenticated attacker can now make the following request to inject arbitrary logs.
curl 'http://localhost:8000/login?next=http://localhost:8000/' -X POST -H 'Content-Type: application/x-www-form-urlencoded' --data-raw $'do=login&username=wrong\'%0a[2024-01-05 02:49:19] HACKER PinkDraconian THIS ENTRY HAS BEEN INJECTED&password=wrong&submit=Login'
If we now were to look at the logs again, we see that the entry has successfully been injected. !PoC2
Impact Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act.
Other sources
pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in pyload allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by pyload. Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act. This vulnerability has been patched in version 0.5.0b3.dev77.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pyload-ngto a version that resolves this vulnerability.Fixed in 0.5.0b3.dev77 - Upgrade
Upgrade
pyloadto a version that resolves this vulnerability.Fixed in 0.5.0b3.dev77
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21645?
CVE-2024-21645 is identified as a log injection vulnerability that can be exploited by unauthenticated actors.
How do I fix CVE-2024-21645?
To remediate CVE-2024-21645, update pyload to a version that addresses the log injection issue, specifically above 0.5.0b3.dev77.
Who is affected by CVE-2024-21645?
CVE-2024-21645 affects users of pyload versions up to 0.5.0b3.dev77 and certain previous versions.
What kind of attacks can exploit CVE-2024-21645?
Exploitation of CVE-2024-21645 allows attackers to inject arbitrary log messages, which could mislead developers or administrators.
Is CVE-2024-21645 a remote vulnerability?
Yes, CVE-2024-21645 can be exploited remotely by any unauthenticated user with access to the logging system.