Horizon Alert
Summary of the vulnerability and why it matters
A critical remote code execution vulnerability has been identified in the REDCap platform's survey and data import functionalities, potentially allowing unauthenticated attackers to execute arbitrary code on servers. The issue arises from manipulating HTTP requests and providing a crafted file path during import handling, which could compromise server security.
- Unauthenticated code execution threat in survey data handling.
- Significant impact if exploited, affecting server integrity.
- Verify REDCap exposure and potential impact on operations.
Attack Path
How an attacker could exploit the issue
An attacker could achieve remote code execution on the REDCap server by sending specially crafted HTTP requests. This attack targets the survey passthrough routing and Data Import logic. By manipulating requests to access unintended controller routes from a public survey, and then providing a crafted file-path or stream parameter during data import, an unauthenticated attacker could trigger the vulnerability. Successful exploitation allows arbitrary code to be run on the server, provided the attacker knows a valid public survey hash.
- Entry condition: Public survey hash known.
- Trigger point: Manipulated HTTP requests and crafted import parameters.
- Resulting risk: Arbitrary code execution on server.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated attacker to execute arbitrary code on the REDCap server by manipulating HTTP requests, provided they know a valid public survey hash. This could affect the integrity and availability of the REDCap server itself.
- REDCap server code execution.
- Malicious HTTP requests and crafted file paths.
- Server compromise and unauthorized actions.
Operational Fix
Recommended remediation, mitigation, and detection steps
Teams responsible for REDCap instances, including application administrators and infrastructure support, must first identify all deployed REDCap environments and confirm exposure. Understanding which surveys are public and accessible via a hash is critical for assessing risk. Subsequent steps will involve coordinating with the vendor and planning remediation during a maintenance window, prioritizing instances with greater exposure or business criticality.
- Own REDCap instance and survey exposure.
- Verify public survey hash accessibility.
- Plan vendor coordination and remediation.