CVE-2024-41961: GHSL-2024-098: Authenticated remote code execution in Elektra - CVE-2024-41961
Authenticated Elektra users were able to execute arbitrary code and potentially access otherwise unreachable remote systems; attackers could have also triggered code execution by sending crafted links to authenticated users.
Other sources
Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an eval sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9554e486bc02.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Elektrato a version that resolves this vulnerability.Patch 8bce00be93b95a6512ff68fe86bf9554e486bc02
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41961?
CVE-2024-41961 is classified as a code injection vulnerability that can lead to severe security risks if exploited.
How do I fix CVE-2024-41961?
To fix CVE-2024-41961, update to a version of Elektra that includes the security patches addressing this vulnerability.
Who is affected by CVE-2024-41961?
CVE-2024-41961 affects authenticated users of the Elektra web application running versions prior to 8bce00be93b95a6512ff68fe86bf9554e486bc02.
What type of vulnerability is CVE-2024-41961?
CVE-2024-41961 is a code injection vulnerability specifically found in the live search functionality of the Elektra web application.
Can CVE-2024-41961 be exploited remotely?
CVE-2024-41961 requires authentication, so an attacker would need to be a logged-in user to exploit the vulnerability.