Cyber Resilience

CVE-2024-49379

Medium

Published: 13 November 2024

Published
13 November 2024
Modified
15 April 2026
KEV Added
Patch
CVSS Score v4 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0655 91.3th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-49379 is a medium-severity Cross-site Scripting (CWE-79) vulnerability in Github (inferred from references). Its CVSS base score is 5.3 (Medium).

Operationally, ranked in the top 8.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis

Umbrel is a home server OS for self-hosting that contained a reflected cross-site scripting vulnerability in its login functionality prior to version 1.2.2. The flaw resides in use-auth.tsx and is triggered when a malicious redirect query parameter is supplied; specifically, a javascript: URL causes attacker-controlled script to execute after a user submits valid credentials.

An unauthenticated attacker can craft a link containing the malicious redirect parameter and deliver it to a target user. Once the victim authenticates, the injected JavaScript runs in the user's session context, enabling actions such as theft of session data or other client-side manipulation without requiring further privileges.

The issue is resolved in Umbrel 1.2.2, as noted in the project's release notes and the associated commit that addresses the redirect handling. The corresponding GitHub Security Lab advisory provides additional technical detail on the root cause.

EPSS for this CVE remains flat at 0.0655 with no material increase observed since disclosure.

EU & UK References

Vulnerability details

Umbrel is a home server OS for self-hosting. The login functionality of Umbrel before version 1.2.2 contains a reflected cross-site scripting (XSS) vulnerability in use-auth.tsx. An attacker can specify a malicious redirect query parameter to trigger the vulnerability. If a…

more

JavaScript URL is passed to the redirect parameter the attacker provided JavaScript will be executed after the user entered their password and clicked on login. This vulnerability is fixed in 1.2.2.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

Github
inferred from references and description; NVD did not file a CPE for this CVE

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-79

Penetration testing submits XSS payloads to web applications, detecting cross-site scripting flaws for subsequent remediation.

addresses: CWE-79

Validates web inputs to reject script-related content that could produce XSS.

addresses: CWE-79

Output validation against expected content can reject or sanitize script content in generated web pages, reducing XSS exploitability.

References