CVE-2024-28111: CSV Injection in exported history CSV files

Published Mar 6, 2024
·
Updated

Canarytokens helps track activity and actions on a network. Canarytokens.org supports exporting the history of a Canarytoken's incidents in CSV format. The generation of these CSV files is vulnerable to a CSV Injection vulnerability. This flaw can be used by an attacker who discovers an HTTP-based Canarytoken to target the Canarytoken's owner, if the owner exports the incident history to CSV and opens in a reader application such as Microsoft Excel. The impact is that this issue could lead to code execution on the machine on which the CSV file is opened. Version sha-c595a1f8 contains a fix for this issue.

Affected Software

2 affected components
Canarytokens Canarytokens
Thinkst Canarytokens<sha-c595a1f8

Event History

Mar 6, 2024
CVE Published
via MITRE·09:15 PM
Data Sourced
via MITRE·09:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-28111?

CVE-2024-28111 is classified as a medium severity vulnerability due to its potential for exploitation via CSV Injection.

2

How do I fix CVE-2024-28111?

To fix CVE-2024-28111, ensure proper sanitization of data before generating CSV files to prevent injection attacks.

3

What software is affected by CVE-2024-28111?

CVE-2024-28111 affects the Canarytokens product from Canarytokens.

4

What can an attacker do with CVE-2024-28111?

An attacker can exploit CVE-2024-28111 to execute arbitrary commands on a victim's machine by tricking them into opening a malicious CSV file.

5

Is there a workaround for CVE-2024-28111 before a patch is available?

A temporary workaround for CVE-2024-28111 is to avoid opening untrusted CSV files and to validate their contents before use.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203