CVE-2024-42364 affects the default setup of Homepage 0.9.1, a customizable homepage application with Docker and service API integrations. In the default configuration, Homepage is deployed without TLS certificate protection and without authentication, which makes the web interface susceptible to DNS rebinding attacks. In a typical attack, an attacker induces a victim to visit an attacker-controlled website. The attacker then changes DNS resolution for their domain from an attacker-controlled IP to an internal IP address hosting the victim's Homepage instance. By probing candidate internal addresses via rebinding, the attacker can identify reachable targets and then cause the victim browser to fetch the attacker domain after it resolves to the internal Homepage service. Because the browser still treats the request as same-origin with the attacker domain, the attacker-controlled script can read the response returned by the internal Homepage instance. The issue enables unauthorized access to sensitive data exposed by the Homepage interface; the provided content specifically notes private information including API keys, with API key exposure reportedly fixed after the first report.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Ruby exploit script (CVE-2024-42364.rb) targeting a critical SQL injection vulnerability (CVE-2024-42364) in Discourse versions prior to 3.2.3 and 3.3.0.beta4. The exploit automates the process of detecting the vulnerability, determining the backend database type (PostgreSQL, MySQL, or SQLite), and performing various SQL injection techniques (union-based, boolean-based, time-based, and error-based) via the search parameter. It attempts to extract sensitive data and test for privilege escalation. The script handles CSRF tokens, session cookies, and supports optional proxy configuration. Results are output to a local JSON file. The repository is structured with the main exploit script, a license, a .gitignore, and a minimal README. The exploit is operational and suitable for authorized penetration testing of vulnerable Discourse instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.