This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: OneUptime < 10.0.18 allows executing untrusted code in Node.js `vm` module. ๐ **Consequences**: Sandbox escape, Remote Code Execution (RCE), and total cluster compromise.โฆ
๐ก๏ธ **Root Cause**: CWE-94 (Code Injection). ๐ **Flaw**: Unsafe execution of user-supplied code within the Node.js `vm` module. The sandbox is effectively broken, allowing code to break out. โ ๏ธ
๐ **Privileges**: Full system access. ๐ **Data**: Complete cluster takeover. ๐ฅ๏ธ **Action**: Hackers can execute arbitrary commands remotely. ๐ซ No restrictions on what they can do once inside.
Q5Is exploitation threshold high? (Auth/Config)
๐ **Auth Required**: Yes. โ๏ธ **Level**: Low Privileges (PR:L). ๐ **Access**: Network (AV:N). ๐ถ **UI**: None required (UI:N). ๐ **Complexity**: Low (AC:L). Easy to exploit if you have basic login access.
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ **Public Exploit**: No PoC provided in data. ๐ต๏ธ **Status**: Advisory confirmed via GitHub (GHSA-h343-gg57-2q67). ๐ซ **Wild Exploit**: Unknown, but severity suggests high risk if weaponized.
Q7How to self-check? (Features/Scanning)
๐ **Check**: Verify your OneUptime version. ๐ **Scan**: Look for Node.js `vm` module usage in custom scripts. ๐ ๏ธ **Feature**: Check if users can inject code into monitoring scripts.โฆ
โ **Fixed**: Yes. ๐ **Patch**: Upgrade to **OneUptime 10.0.18** or newer. ๐ข **Source**: Official GitHub Security Advisory. ๐ก๏ธ Immediate update recommended.
Q9What if no patch? (Workaround)
๐ง **Workaround**: Disable user script execution features. ๐ซ **Mitigation**: Restrict access to the `vm` module. ๐ **Isolate**: Segment the cluster to limit lateral movement.โฆ