OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase. This issue has been patched in version 10.0.42.
The vulnerability classified as CWE-306 (missing authentication for critical function) consists in the fact that endpoints responsible for testing notifications and managing phone numbers do not require any authentication. An attacker with network access can directly send requests to these endpoints, initiating the sending of SMS messages, voice calls, emails or WhatsApp messages, as well as purchasing phone numbers at the platform operator's expense.
Attackers can abuse the platform to mass send messages through various communication channels (SMS, calls, email, WhatsApp) and generate costs through unauthorized purchase of phone numbers, as well as violate the confidentiality and integrity of notification configurations.
OneUptime should be updated to version 10.0.42 or newer, where the vulnerability has been patched. The patch is available in the project repository on GitHub (commit 9adbd04538714740506708d6fa610e433be4d2a4) as well as the official 10.0.42 release.
Hackerbay OneUptime in versions prior to 10.0.42
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHackerbay Oneuptime
APPHackerbay< 10.0.40
Related vulnerabilities
Brak uwierzytelnienia w API powiadomień OneUptime — obejście autoryzacji
Brak uwierzytelnienia w endpointach workflow w OneUptime (RCE)
RCE w OneUptime — command injection przez Playwright w Synthetic Monitor
SQL Injection w OneUptime — nieautoryzowany dostęp do bazy i potencjalny RCE
OneUptime: RCE przez niebezpieczny Playwright sandbox w Synthetic Monitors