If you updated Chrome and SolarWinds Web Help Desk recently, get ready to update again – both have new flaws. And popular WordPress plugin and AWS's Application Load Balancer also have critical vulnerabilities. I’m Justin Fraction for eSecurity Planet. Let’s get into it. First Up: Critical WordPress Vulnerability Jeopardizes Millions of Sites Vulnerability Type: Privilege Escalation LiteSpeed Cache, a WordPress plugin designed to speed up caching and optimize page loads, has a vulnerability that puts over 5 million WordPress instances at risk.
A member of the PatchStack Alliance discovered this flaw, which was then reported to LiteSpeed Technologies. The issue lies in a user simulation feature that uses a weak security hash. This allows unauthenticated users to escalate their privileges and potentially upload malicious plugins or files. The fix: Upgrade to LiteSpeed version 6.4.1, which includes the necessary patch. Next Up: AWS Application Load Balancer Sees Configuration Issues Type of vulnerability: Configuration issue leading to authentication bypass.
The problem: A configuration vulnerability in Amazon Web Services' Application Load Balancer (ALB) authentication feature, discovered by Miggo, could allow a threat actor to bypass ALB security. If an application is misconfigured as an ALB target group and is directly accessible, attackers could exploit a shared public key server to set an arbitrary key ID. This vulnerability, dubbed ALBeast, stems from a lack of guidance on validating a token’s signer in AWS’s documentation, potentially leading applications to trust attacker-crafted tokens.
Applications exposed to the internet are especially vulnerable. AWS has since updated its documentation and added code to ensure authentication signatures are verified and validated. However, AWS does not consider this issue a formal vulnerability and is reaching out to customers with suboptimal configurations rather than altering the entire ALB component. The fix: Follow AWS's updated documentation and implement the new code for signature validation.
This ensures your applications are protected against potential exploits. At eSecurity Planet, we always recommend staying informed about vulnerabilities to protect your systems and networks. Check out our article on top Vulnerability Scanners and explore the links in the description! And back to the updates… Upgrade Chrome As Soon As Possible Type of vulnerability: Type confusion. The problem: A bug in the V8 JavaScript and Web Assembly engine impacts Google Chrome on PCs.
This vulnerability allows remote attackers to exploit heap correction using specifically crafted HTML pages, potentially taking control of your Chrome instance. Tracked as CVE-2024-7971, it affects versions of Chrome prior to 128.0.6613.84. The fix: Google’s stable channel updates include versions 128.0.6613.84/.85 for Windows and Mac, and 128.0.6613.84 for Linux. To update: Open Chrome and click the three vertical dots in the upper-right corner.
Select Help, then About Chrome. If an update is available, Chrome will automatically update. Click Relaunch to apply it. Another SolarWinds Web Help Desk Flaw Has Emerged Type of vulnerability: Hardcoded credential. The problem: Last week, on eSecurity Planet, writer Jenna Phipps mentioned a Java deserialization flaw in SolarWinds Web Help Desk. This week, researchers have discovered another vulnerability in WHD, this one a hardcoded credential issue.
If exploited, it allows an unauthenticated remote user to access the Web Help Desk’s controls and modify its data. Zach Hanley of Horizon3.ai discovered and reported the vulnerability. The flaw is tracked as CVE-2024-28987 and has a CVSS score of 9.1. The fix: SolarWinds has released a hotfix, 12.8.3 number 2, that solves both last week’s remote code execution vulnerability and this week’s credential one. CISA Adds Versa Director Vulnerability to Catalog Type of vulnerability: Dangerous file type upload vulnerability.
The problem: Versa Networks’ Director product has GUI customization options available for users who have Provider-Data-Center-Admin or Provider-Data-Center-System-Admin permissions. According to NIST, a malicious user with those privileges could use the “Change Favicon” option within the GUI to upload a malicious file that has a .png extension. The file would masquerade as an image file, according to NIST. The exploit is only possible after a user with the correct privileges has logged into the Versa Director GUI successfully.
Versa Networks noted that managed service providers are likely to be the main targets. The vulnerability is tracked as CVE-2024-39717 and has a severity rating of 6.6. The CISA has added this vulnerability to its catalog of Known Exploited Vulnerabilities (KEV). It has a High severity rating. According to NIST, Versa Networks is aware of one instance where the vulnerability was exploited because the customer didn’t implement older firewall guidelines.
The fix: To remediate CVE-2024-39717, upgrade to one of the following updated versions, with links to the download page provided by Versa Networks down in the description: 21.2.3: 22.1.2: 22.1.3: 22.1.4: Not affected. Additionally, follow all of Versa Networks’ firewall guidelines and hardening best practices. Double RCE Vulnerabilities Affect GPS Tracking Tool Traccar [Tracker] Type of vulnerability: Path traversal leading to potential remote code execution.
The problem: Open-source GPS tracking solution Traccar has two path traversal vulnerabilities that could allow unauthenticated threat actors to execute code remotely. According to Horizon3.ai, Traccar is vulnerable when guest registration is enabled, which is its default configuration. Traccar allows users to register their devices to be tracked, and Traccar shows their location when the devices communicate with the Traccar server. In version 5.1 of the solution, an image upload feature allows users to upload a picture of their device, but Traccar’s code has vulnerabilities in managing image file uploads.
The first vulnerability is tracked as CVE-2024-24809 and has a CVSS score of 8.5, with a high rating. The second is tracked as CVE-2024-31214 and has a critical CVSS score of 9.7. Both allow remote code execution if exploited. According to Horizon3.ai researcher, Naven Sunkavally, “The net result of CVE-2024-31214 and CVE-2024-24809 is that an attacker can place files with arbitrary content anywhere on the file system,” he said. “However, an attacker only has partial control over the filename.” The filename has to be a particular structure for the attackers to be successful.
The fix: Naveen recommends upgrading to Traccar 6. Alternatively, you can switch the registration setting to false, so user self-registration isn’t automatically enabled. That wraps up our list of security updates you should fix for late August 2024. Remember, staying informed about these vulnerabilities is crucial for protecting your systems and data. Be sure to apply the recommended fixes and updates as soon as possible. For more in-depth cybersecurity news and analysis, visit our website, at eSecurity Planet.
Don't forget to like, subscribe, and hit the notification bell to stay up-to-date with the latest security insights. Thanks for watching, and stay safe!