CVE-2024-41961: GHSL-2024-098: Authenticated remote code execution in Elektra - CVE-2024-41961

Published Aug 1, 2024
·
Updated

Authenticated Elektra users were able to execute arbitrary code and potentially access otherwise unreachable remote systems; attackers could have also triggered code execution by sending crafted links to authenticated users.

Other sources

Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing Ruby code, which later flows into an eval sink which executes the code. Fixed in commit 8bce00be93b95a6512ff68fe86bf9554e486bc02.

— MITRE

Affected Software

1 affected component
Openstack Elektra

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Elektra to a version that resolves this vulnerability.

    Patch 8bce00be93b95a6512ff68fe86bf9554e486bc02

Event History

Aug 1, 2024
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Sep 21, 2026
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2024-41961?

CVE-2024-41961 is classified as a code injection vulnerability that can lead to severe security risks if exploited.

2

How do I fix CVE-2024-41961?

To fix CVE-2024-41961, update to a version of Elektra that includes the security patches addressing this vulnerability.

3

Who is affected by CVE-2024-41961?

CVE-2024-41961 affects authenticated users of the Elektra web application running versions prior to 8bce00be93b95a6512ff68fe86bf9554e486bc02.

4

What type of vulnerability is CVE-2024-41961?

CVE-2024-41961 is a code injection vulnerability specifically found in the live search functionality of the Elektra web application.

5

Can CVE-2024-41961 be exploited remotely?

CVE-2024-41961 requires authentication, so an attacker would need to be a logged-in user to exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203