Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a security vulnerability in the OneUptime monitoring platform that could allow an unauthenticated attacker to disrupt alerting services. The issue involves unprotected API endpoints that, when combined with a separate information leak, could enable an attacker to manipulate phone numbers associated with a victim's Twilio account. The vulnerability has been addressed in the latest version of OneUptime.
- Unprotected APIs could disrupt alerting services.
- Protects against unauthorized access to critical services.
- Confirm relevance and exposure to OneUptime.
Attack Path
How an attacker could exploit the issue
An attacker could target the OneUptime monitoring platform by first leveraging a leaked project ID from a public Status Page API. This exposure, combined with unauthenticated notification API endpoints, allows an attacker to interact with the system's communication channels. By exploiting this, an attacker could potentially compromise a victim's Twilio account, enabling them to purchase phone numbers and disrupt existing alerting configurations.
- No authentication required.
- Reachable notification API endpoints.
- Potential for account takeover.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, unauthenticated attackers could interact with unprotected notification API endpoints. This could potentially lead to unauthorized actions on a victim's Twilio account.
- System data could be affected.
- Unprotected API endpoints could be accessed.
- Phone numbers could be purchased or deleted.
Operational Fix
Recommended remediation, mitigation, and detection steps
The OneUptime platform's notification API endpoints require immediate attention from teams managing externally facing services. The first practical step involves identifying all OneUptime instances, confirming their external reachability and business criticality, and then locating the specific asset owners responsible for each instance to prioritize remediation efforts.
- Platform and Security teams own this.
- Verify external reachability and asset owners.
- Plan coordinated remediation based on risk.