CVE-2024-39899
MEDIUMPrivateBin 1.5.0-1.7.3 - Authentication Bypass via YOURLS Proxy URL Validation
Title source: llmDescription
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. In v1.5, PrivateBin introduced the YOURLS server-side proxy. The idea was to allow using the YOURLs URL shortener without running the YOURLs instance without authentication and/or exposing the authentication token to the public, allowing anyone to shorten any URL. With the proxy mechanism, anyone can shorten any URL pointing to the configured PrivateBin instance. The vulnerability allowed other URLs to be shortened, as long as they contain the PrivateBin instance, defeating the limit imposed by the proxy. This vulnerability is fixed in 1.7.4.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/PrivateBin/PrivateBin/security/advisories/GHSA-mqqj-fx8h-437j
Issue Tracking x_refsource_misc
https://github.com/PrivateBin/PrivateBin/pull/1370
Scores
CVSS v3
5.3
EPSS
0.0063
EPSS Percentile
45.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-305
CWE-791
Status
published
Products (2)
privatebin/privatebin
1.5.0 - 1.7.4Packagist
PrivateBin/PrivateBin
>= 1.5.0, < 1.7.4
Published
Jul 09, 2024
Tracked Since
Feb 18, 2026