PT-2024-22798 · Oneuptime · Oneuptime

·

CVE-2024-29194

·

Published

2024-03-24

·

Updated

2025-12-05

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions OneUptime versions prior to 7.0.1815
Description The issue lies in the improper validation of client-side stored data within the web application. Specifically, the is master admin key, stored in the local storage of the browser, can be manipulated by an attacker. By changing this key from false to true, the application grants administrative privileges to the user, without proper server-side validation. This allows unauthorized access to administrative functionalities and represents a high security risk. An attacker could see the list of users who signed up to OneUptime.
Recommendations For versions prior to 7.0.1815, update to version 7.0.1815 to resolve the issue. As a temporary workaround, consider restricting access to the is master admin key in the local storage to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-29194
GHSA-246P-XMG8-WMCQ

Affected Products

Oneuptime