Vulnerability record · CVE-2024-3408 · published 6 June 2024
CVE-2024-3408: D-Tale hardcoded SECRET_KEY enables auth bypass and RCE
Man · D Tale
man-group/dtale 3.10.0 ships a hardcoded Flask SECRET_KEY, letting attackers forge session cookies when authentication is enabled. The same release fails to restrict custom filter queries, so the /update-settings endpoint can be abused to run arbitrary code even when enable_custom_filters is off. Both flaws combine into full authentication bypass and remote code execution.
Description
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attackers to forge a session cookie if authentication is enabled. Additionally, the application fails to properly restrict custom filter queries, enabling attackers to execute arbitrary code on the server by bypassing the restriction on the `/update-settings` endpoint, even when `enable_custom_filters` is not enabled. This vulnerability allows attackers to bypass authentication mechanisms and execute remote code on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no privileges or interaction required, public exploit reference, and very high EPSS make this an urgent patch-first issue.
What it is
man-group/dtale 3.10.0 ships a hardcoded Flask SECRET_KEY, letting attackers forge session cookies when authentication is enabled. The same release fails to restrict custom filter queries, so the /update-settings endpoint can be abused to run arbitrary code even when enable_custom_filters is off. Both flaws combine into full authentication bypass and remote code execution.
Impact
An unauthenticated attacker can forge a valid session, bypass login, and execute arbitrary code on the server, gaining full control of the host and any data it can reach.
Attack surface
Reached over the network via the Flask web interface; the CVSS vector shows no privileges or user interaction required, and the description states the cookie forgery applies when authentication is enabled while the filter bypass works regardless of the enable_custom_filters setting.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.77951 (99.55th percentile) and a public Huntr exploit reference exists, indicating high likelihood of active exploitation.
What to do
- Upgrade dtale past 3.10.0 using the fix commit 32bd6fb4a63de779ff1e51823a456865ea3cbd13 or a later release.
- Replace the hardcoded SECRET_KEY with a unique, randomly generated value per deployment and rotate any existing sessions.
- Disable or restrict the /update-settings endpoint and custom filter functionality until patched.
- Do not expose dtale directly to untrusted networks; place it behind authentication and network controls.
- Monitor for forged session cookies and unexpected code execution on dtale hosts.
Detection
- Inspect Flask session cookies for signatures that validate against the default hardcoded SECRET_KEY.
- Alert on POST requests to /update-settings, especially with custom filter payloads.
- Monitor dtale processes for unexpected child processes or outbound connections indicating code execution.
- Review web logs for authentication bypass patterns such as valid sessions without a prior login.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/man-group/dtale/commit/32bd6fb4a63de779ff1e51823a456865ea3cbd13 | |
| https://huntr.com/bounties/57a06666-ff85-4577-af19-f3dfb7b02f91 | ExploitThird Party Advisory |
| https://huntr.com/bounties/57a06666-ff85-4577-af19-f3dfb7b02f91 | ExploitThird Party Advisory |
Track CVE-2024-3408 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-3408), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.