VDB
Sign up
LOW

GHSA-23q2-5gf8-gjpp

Enabling Authentication does not close all logged in socket connections immediately

Quick fix

GHSA-23q2-5gf8-gjpp — uptime-kuma: upgrade to the fixed version with the command below.

npm install uptime-kuma@1.23.12

Details

### Summary This is basically [GHSA-88j4-pcx8-q4q](https://github.com/louislam/uptime-kuma/security/advisories/GHSA-88j4-pcx8-q4q3) but instead of changing passwords, when enabling authentication.

### PoC - Open Uptime Kuma with authentication disabled - Enable authentication using another window - Access the platform using the previously logged-in window - Note that access (read-write) remains despite the enabled authentication - Expected behaviour: - After enabling authentication, all previously connected sessions should be invalidated, requiring users to log in. - Actual behaviour: - The system retains sessions and never logs out users unless explicitly done by clicking logout or refreshing the page.

### Impact See [GHSA-g9v2-wqcj-j99g](https://github.com/louislam/uptime-kuma/security/advisories/GHSA-g9v2-wqcj-j99g) and [GHSA-88j4-pcx8-q4q](https://github.com/louislam/uptime-kuma/security/advisories/GHSA-88j4-pcx8-q4q3)

TBH this is quite a niche edge case, so I don't know if this even warrants a security report.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/uptime-kuma
Introduced in: 0Fixed in: 1.23.12
Fixnpm install uptime-kuma@1.23.12

References