CVE-2024-21645: pyLoad Log Injection

Published Jan 8, 2024
·
Updated

Summary A log injection vulnerability was identified in pyload. This vulnerability allows any unauthenticated actor to inject arbitrary messages into the logs gathered by pyload.

Details pyload will generate a log entry when attempting to sign in with faulty credentials. This entry will be in the form of Login failed for user 'USERNAME'. However, when supplied with a username containing a newline, this newline is not properly escaped. Newlines are also the delimiter between log entries. This allows the attacker to inject new log entries into the log file.

PoC Run pyload in the default configuration by running the following command pyload

We can now sign in as the pyload user and view the logs at http://localhost:8000/logs. !Viewing the logs

Any unauthenticated attacker can now make the following request to inject arbitrary logs.

curl 'http://localhost:8000/login?next=http://localhost:8000/' -X POST -H 'Content-Type: application/x-www-form-urlencoded' --data-raw $'do=login&username=wrong\'%0a[2024-01-05 02:49:19] HACKER PinkDraconian THIS ENTRY HAS BEEN INJECTED&password=wrong&submit=Login'

If we now were to look at the logs again, we see that the entry has successfully been injected. !PoC2

Impact Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act.

Other sources

pyLoad is the free and open-source Download Manager written in pure Python. A log injection vulnerability was identified in pyload allowing any unauthenticated actor to inject arbitrary messages into the logs gathered by pyload. Forged or otherwise, corrupted log files can be used to cover an attacker’s tracks or even to implicate another party in the commission of a malicious act. This vulnerability has been patched in version 0.5.0b3.dev77.

— MITRE

Affected Software

4 affected componentsFixes available
pip/pyload-ng<0.5.0b3.dev77
0.5.0b3.dev77
pyload pyload<=0.4.9
pyload pyload=0.5.0-beta1
pyload pyload=0.5.0-beta2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/pyload-ng to a version that resolves this vulnerability.

    Fixed in 0.5.0b3.dev77
  2. Upgrade

    Upgrade pyload to a version that resolves this vulnerability.

    Fixed in 0.5.0b3.dev77

Event History

Jan 8, 2024
CVE Published
via MITRE·01:20 PM
Data Sourced
via MITRE·01:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
03:29 PM

Frequently Asked Questions

1

What is the severity of CVE-2024-21645?

CVE-2024-21645 is identified as a log injection vulnerability that can be exploited by unauthenticated actors.

2

How do I fix CVE-2024-21645?

To remediate CVE-2024-21645, update pyload to a version that addresses the log injection issue, specifically above 0.5.0b3.dev77.

3

Who is affected by CVE-2024-21645?

CVE-2024-21645 affects users of pyload versions up to 0.5.0b3.dev77 and certain previous versions.

4

What kind of attacks can exploit CVE-2024-21645?

Exploitation of CVE-2024-21645 allows attackers to inject arbitrary log messages, which could mislead developers or administrators.

5

Is CVE-2024-21645 a remote vulnerability?

Yes, CVE-2024-21645 can be exploited remotely by any unauthenticated user with access to the logging system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203