2025-04-07 16:03:58 +00:00

60 lines
1.8 KiB
JSON

{
"id": "CVE-2024-38392",
"sourceIdentifier": "cve@mitre.org",
"published": "2025-04-02T21:15:31.170",
"lastModified": "2025-04-07T14:18:49.830",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Pexip Infinity Connect before 1.13.0 lacks sufficient authenticity checks during the loading of resources, and thus remote attackers can cause the application to run untrusted code."
},
{
"lang": "es",
"value": "PEXIP Infinity Connect antes de 1.13.0 carece de verificaciones de autenticidad suficientes durante la carga de recursos y, por lo tanto, los atacantes remotos pueden hacer que la aplicaci\u00f3n ejecute c\u00f3digo no confiable."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
"baseScore": 9.1,
"baseSeverity": "CRITICAL",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 3.9,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-863"
}
]
}
],
"references": [
{
"url": "https://docs.pexip.com/admin/security_bulletins.htm",
"source": "cve@mitre.org"
}
]
}