CVE-2024-3164
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet. This would share database username and password under Log Files and download DB Dump and other dotCMS Content under Tools. Nothing in the System → Maintenance should be displayed for users with site admin role. Only system admins must have access to System Maintenance.
OWASP Top 10 - A01) Broken Access Control
Leer descripción completaMostrar menos
OWASP Top 10 - A04) Insecure Design
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
- Puntuación base: 4.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.47%
- Percentil entre todas las CVEs puntuadas: 39
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-284
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-3164",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-3164",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-07-17T20:19:19.811850Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@dotcms.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "security@dotcms.com",
"affectedData": [
{
"vendor": "dotCMS",
"product": "dotCMS core",
"versions": [
{
"status": "affected",
"version": "22.02 and after"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:dotcms:dotcms:22.02:*:*:*:*:*:*:*"
],
"vendor": "dotcms",
"product": "dotcms",
"versions": [
{
"status": "affected",
"version": "22.02"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-04-01T22:15:22.507",
"references": [
{
"url": "https://github.com/dotCMS/core/issues/27909",
"tags": [
"Issue Tracking"
],
"source": "security@dotcms.com"
},
{
"url": "https://github.com/dotCMS/core/pull/27912",
"tags": [
"Issue Tracking"
],
"source": "security@dotcms.com"
},
{
"url": "https://www.dotcms.com/security/SI-69",
"tags": [
"Broken Link"
],
"source": "security@dotcms.com"
},
{
"url": "https://github.com/dotCMS/core/issues/27909",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/dotCMS/core/pull/27912",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.dotcms.com/security/SI-69",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@dotcms.com",
"description": [
{
"lang": "en",
"value": "CWE-284"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is and always has been an Admin portlet, is accessible to anyone with that portlet and not just to CMS Admins. Users that get site admin but not a system admin, should not have access to the System Maintenance → Tools portlet. This would share database username and password under Log Files and download DB Dump and other dotCMS Content under Tools. Nothing in the System → Maintenance should be displayed for users with site admin role. Only system admins must have access to System Maintenance.\n\nOWASP Top 10 - A01) Broken Access Control\n\nOWASP Top 10 - A04) Insecure Design"
},
{
"lang": "es",
"value": "En el panel de dotCMS, las pestañas Tools y Log Files en System->Maintenance-> Log Files, que es y siempre ha sido un portlet de administración, son accesibles para cualquier persona con ese portlet y no solo para los administradores de CMS. Los usuarios que obtienen un administrador del sitio pero no un administrador del sistema no deberían tener acceso al portlet System Maintenance ? Tools. Esto compartiría el nombre de usuario y la contraseña de la base de datos en Archivos de registro y descargaría DB Dump y otro contenido de dotCMS en Herramientas. No se debe mostrar nada en System ? Maintenance para los usuarios con función de administrador del sitio. Sólo los administradores del sistema deben tener acceso al Mantenimiento del sistema. OWASP Top 10 - A01) Control de acceso roto OWASP Top 10 - A04) Diseño inseguro"
}
],
"lastModified": "2026-06-17T07:43:26.503",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8156D65-B011-4B9A-BF2E-F7F3CCFA8BD7",
"versionEndExcluding": "22.03.15",
"versionStartIncluding": "22.02"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4513A2EB-037F-4037-B4F7-44B8AECB407A",
"versionEndExcluding": "23.01.15",
"versionStartIncluding": "23.01"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E85B4224-34E8-47CD-8F08-8B129868AF1F",
"versionEndIncluding": "23.09.7",
"versionStartIncluding": "23.02"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33DBCA2A-D4E2-4AE6-B6E0-FD0A277266F4"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "342C11DD-7760-42AE-8670-4461ECB51E4C"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90B73A81-7202-4B0B-822B-4F2EE4480663"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BFA7220-B846-451B-A7B2-C3DC87767575"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "258813CA-66A7-4DCA-883D-884FB88430DC"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E69C8B72-A38C-4D97-83BB-DCE392D3ABD0"
},
{
"criteria": "cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5309F19-2D65-4E87-87FD-2A0294008FF5"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@dotcms.com"
}