CVE-2024-3408 is a critical vulnerability affecting man-group/dtale version 3.10.0, enabling both authentication bypass and remote code execution (RCE). This flaw stems from a hardcoded SECRET_KEY in the Flask configuration, allowing attackers to forge session cookies, and improper validation of custom filter queries, which permits arbitrary code execution even when custom filters are disabled. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.917, this vulnerability presents a severe risk, allowing unauthenticated attackers to achieve full compromise of affected systems with low attack complexity. While not yet listed in CISA's KEV catalog, exploit modules are available in Metasploit and Nuclei, indicating a high likelihood of exploitation, despite minimal public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.10.0CPE matchmatch criteria | cpe:2.3:a:man:d-tale:3.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.