HomeDfir-IrisCVE-2024-25624

CVE-2024-25624

MEDIUM
6.8CVSS
Published: 2024-04-25
Updated: 2024-12-10
AI Analysis

Description

Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of Jinja2 environment, reports generation in `iris-web` is prone to a Server Side Template Injection (SSTI). Successful exploitation of the vulnerability can lead to an arbitrary Remote Code Execution. An authenticated administrator has to upload a crafted report template containing the payload. Upon generation of a report based on the weaponized report, any user can trigger the vulnerability. The vulnerability is patched in IRIS v2.4.6. No workaround is available. It is recommended to update as soon as possible. Until patching, review the report templates and keep the administrative privileges that include the upload of report templates limited to dedicated users.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
high
User Action
required
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-1336CWE-94

Metadata

Primary Vendor
DFIR-IRIS
Published
4/25/2024
Last Modified
12/10/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

dfir-iris : iris

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-25624 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com