OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal server side secrets by misusing the web-hooks. Since the malicious user gets a root shell inside a container this opens up the the infrastructure environment for further attacks and exposures. Version 6.4.11 fixes the issue.
The web-hook mechanism in OpenCTI lacks sufficient code injection protections (CWE-94), which allows a user with the `manage customizations` permission to embed a malicious payload. As a result of its execution, the attacker gains a root shell inside the container running the platform. Additionally, it is possible to read internal server secrets, such as API keys or authentication credentials. The obtained container access can serve as a starting point for further attacks on the environmental infrastructure (lateral movement).
An attacker can gain full control over the container hosting OpenCTI (root shell), read internal server secrets, and potentially extend the attack across the entire environmental infrastructure.
OpenCTI should be updated to version 6.4.11 or later, which contains a fix eliminating the described vulnerability. Before applying the patch, it is worth considering restricting the group of users with the `manage customizations` permission to trusted personnel only.
OpenCTI (Citeum) in all versions prior to 6.4.11
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCiteum Opencti
APPCiteum6.4.8 – 6.4.11 (excl.)
Related vulnerabilities
OpenCTI: privilege escalation umożliwiający dostęp jako dowolny użytkownik
OpenCTI: Wykonanie dowolnego kodu JS przez niesanityzowane szablony EJS
OpenCTI: Pominięcie weryfikacji uprawnień przez nagłówek HTTP
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...