changedetection.io is vulnerable to unauthenticated static path traversal
위협 신호 · CVSS · EPSS · KEV
이론적 심각도 점수
30일 내 악용 확률 예측
실측 악용 기록 없음
2주 이내 패치 — 우선 조치 대상
CVSS 벡터 · 메트릭
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N상세 설명
Summary
The /static/<group>/<filename> route accepts group="..", which causes send_from_directory("static/..", filename) to execute. This moves the base directory up to /app/changedetectionio, enabling unauthenticated local file read of application source files (e.g., flask_app.py). Severity is low information disclosure (C:L).
Details
The vulnerable code is in changedetectionio/flask_app.py inside static_content():
1group = re.sub(r'[^\w.-]+', '', group.lower()) 2filename = re.sub(r'[^\w.-]+', '', filename.lower()) 3... 4return send_from_directory(f"static/{group}", path=filename)The group sanitization allows dots, so group=".." passes validation.
This results in send_from_directory("static/..", filename), effectively shifting the base directory to /app/changedetectionio and allowing reads of files in that directory.
The route is unauthenticated, so any user can retrieve source files without logging in.
Limitation: the route only matches
/static/<group>/<filename>and rejects slashes insidefilename, so it cannot traverse further to arbitrary system paths like/etc/passwd. It is limited to files inside the application package directory.
PoC
- Start an instance (example: Docker on port 5050)
1docker run -d --name cdio -p 127.0.0.1:5050:5000 -v cdio-data:/datastore cdio-local- Reproduce
(URL-encoded traversal)
1curl -i http://127.0.0.1:5050/static/%2e%2e/flask_app.py(curl path passthrough)
1curl --path-as-is -i http://127.0.0.1:5050/static/../flask_app.py- Observe that the response body contains Python source code from
flask_app.py.
Impact
- Vulnerability type: Directory Traversal / Local File Read
- Affected users: Anyone with network access (no authentication required)
- Scope: Source files under
/app/changedetectionio - Security impact: Internal logic exposure can aid further exploitation (Confidentiality: Low)
AI 심층 분석
공격 시나리오 · 재현 가능한 PoC 페이로드 · 즉시 적용 가능한 차단 패치를 한 번에 받아 보세요. 보안 운영팀이 그대로 점검·티켓팅에 쓸 수 있는 형태로 정리해 드립니다.
참고 자료 5
링크 내용 불러오는 중…