CVE-2024-48911: OpenCanary Executes Commands From Potentially Writable Config File
Impact
OpenCanary directly executed commands taken from its config file. Where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change the config file and escalate permissions when root later runs the daemon.
Thanks to the folks at Whirlylabs for finding and fixing this.
Patches
Upgrade to 0.9.4 or higher.
Other sources
OpenCanary, a multi-protocol network honeypot, directly executed commands taken from its config file. Prior to version 0.9.4, where the config file is stored in an unprivileged user directory but the daemon is executed by root, it’s possible for the unprivileged user to change the config file and escalate permissions when root later runs the daemon. Version 0.9.4 contains a fix for the issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48911?
CVE-2024-48911 has been assigned a moderate severity due to the potential for privilege escalation.
How do I fix CVE-2024-48911?
To fix CVE-2024-48911, upgrade OpenCanary to version 0.9.5 or later.
Who is affected by CVE-2024-48911?
Users of OpenCanary versions up to and including 0.9.4 are affected by CVE-2024-48911.
What kind of vulnerability is CVE-2024-48911?
CVE-2024-48911 is a command execution vulnerability that allows unauthorized users to modify configuration files.
Is CVE-2024-48911 present in OpenCanary installations?
Yes, CVE-2024-48911 is present in any OpenCanary installation using version 0.9.4 or earlier.