CVE-2024-27091: GeoNode stored XSS to full account takeover
An issue exists within GEONODE where the current rich text editor is vulnerable to Stored XSS. The applications cookies are set securely, but it is possible to retrieve a victims CSRF token and issue a request to change another user's email address to perform a full account takeover. Due to the script element not impacting the CORS policy, requests will succeed.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/geonodeto a version that resolves this vulnerability.Fixed in 4.2.3 - Upgrade
Upgrade
GeoNodeto a version that resolves this vulnerability.Fixed in 4.2.3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27091?
The severity of CVE-2024-27091 is considered high due to its potential for Stored XSS exploits.
How do I fix CVE-2024-27091?
To fix CVE-2024-27091, upgrade GeoNode to version 4.2.4 or later.
Which versions of GeoNode are affected by CVE-2024-27091?
CVE-2024-27091 affects GeoNode versions up to and including 4.2.3.
What type of vulnerability is CVE-2024-27091?
CVE-2024-27091 is a Stored Cross-Site Scripting (XSS) vulnerability.
What are the potential impacts of CVE-2024-27091?
The potential impacts of CVE-2024-27091 include unauthorized access to user sessions and data hijacking.