OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arbitrary JavaScript in the context of the OpenCTI platform process during notifier template execution. This vulnerability is fixed in 6.9.5.
The safeEjs.ts file responsible for handling EJS templates does not perform proper validation and sanitization of input data (CWE-1336 — improper neutralization of special elements in templates). A user with permission to manage customization can inject malicious JavaScript code into a notifier template. When such a template is executed, the code is interpreted and run directly in the context of the OpenCTI application process on the server.
An attacker can execute arbitrary JavaScript code on the server side, which potentially leads to complete takeover of the platform instance, disclosure of sensitive intelligence data, and violation of system integrity and availability.
OpenCTI should be updated to version 6.9.5 or newer, in which the vulnerability has been fixed. Details are available in the official release: https://github.com/OpenCTI-Platform/opencti/releases/tag/6.9.5
OpenCTI (Citeum) in all versions prior to 6.9.5
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HCiteum Opencti
APPCiteum< 6.9.5
Related vulnerabilities
OpenCTI: privilege escalation umożliwiający dostęp jako dowolny użytkownik
OpenCTI: RCE przez nadużycie web-hooków przez uprzywilejowanego użytkownika
OpenCTI: Pominięcie weryfikacji uprawnień przez nagłówek HTTP
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to ...