Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-24784— Discoverability of user password hash in Statamic CMS

Quick assessment

Affected
statamic cms
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Statamic是美国Statamic公司的一个基于 Laravel 构建的强大的平面文件 Cms。用于将所有内容、模板、资产和设置存储在文件而不是数据库中。 Statamic存在安全漏洞,该漏洞源于在版本 3.2.39 和 3.3.2 之前,可以在 REST API 的用户端点中使用特制的正则表达式过滤器来确认用户密码哈希的单个字符。多个这样的请求最终可以发现整个散列。响应中不存在哈希,但是结果的存在或不存在确认字符是否在正确的位置。默认情况下,API 已启用节流,因此这是一项耗时的任务。 REST A

CVSS 3.7 · Low EPSS 1.03% · P61
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-24784

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Discoverability of user password hash in Statamic CMS
Source: CVE Program / CVE List V5
Vulnerability Description
Statamic is a Laravel and Git powered CMS. Before versions 3.2.39 and 3.3.2, it is possible to confirm a single character of a user's password hash using a specially crafted regular expression filter in the users endpoint of the REST API. Multiple such requests can eventually uncover the entire hash. The hash is not present in the response, however the presence or absence of a result confirms if the character is in the right position. The API has throttling enabled by default, making this a time intensive task. Both the REST API and the users endpoint need to be enabled, as they are disabled by default. The issue has been fixed in versions 3.2.39 and above, and 3.3.2 and above.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
Statamic 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Statamic是美国Statamic公司的一个基于 Laravel 构建的强大的平面文件 Cms。用于将所有内容、模板、资产和设置存储在文件而不是数据库中。 Statamic存在安全漏洞,该漏洞源于在版本 3.2.39 和 3.3.2 之前,可以在 REST API 的用户端点中使用特制的正则表达式过滤器来确认用户密码哈希的单个字符。多个这样的请求最终可以发现整个散列。响应中不存在哈希,但是结果的存在或不存在确认字符是否在正确的位置。默认情况下,API 已启用节流,因此这是一项耗时的任务。 REST A
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
statamic cms < 3.2.39 -

II. Public POCs for CVE-2022-24784

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-24784

登录查看更多情报信息。

Patches & Fixes for CVE-2022-24784 (1)

Vendor Advisories for CVE-2022-24784 (1)

Other References for CVE-2022-24784 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-24784

No comments yet


Leave a comment