Patch
CVE-2024-7093
with vRx
Overview
A Server-Side Template Injection vulnerability was discovered in in Dispatch Message Templates.
Impact
Authenticated users can achieve Remote Code Execution (RCE) via Server-Side Template Injection (SSTI) using Dispatch's notification functionality if their instance contains an enabled message template containing malicious code.
Admin users have full access to create, edit, and delete these message templates. Non-admins can also exploit this vulnerability if they are the first to create a message template as they do not have the permissions to edit an existing message template.
All versions of Dispatch before the pull request: https://github.com/Netflix/dispatch/pull/5002, are impacted and should be patched immediately.
Description
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line scripts in their custom message templates, which are then executed whenever these notifications are rendered and sent out.
Workarounds and Fixes
This issue was fixed in the PR, https://github.com/Netflix/dispatch/pull/5002. Ensure to upgrade your Dispatch instances to the new version.
It can be done as follows:
git clone https://github.com/Netflix/dispatch.git
References
https://github.com/Netflix/dispatch
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-003.md
Read more
Read less
Patch faster and smarter
with vRx
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
More than 600 customers trust vRx:




Solution
Remediate faster with vRx
Patch Management
vRx automatically deploys patches across all systems, cutting patching time by 80%.
Scripting Engine
vRx’s scripting engine solves complex vulnerabilities, like log4j, with built-in or custom scripts.
Patchless Protection
vRx’s Patchless Protection secures vulnerable apps and reduces risk while maintaining functionality.

Automated Patching, Scripting, and more
Talk with our team to get a personal walkthrough
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.