CVE-2024-21622
CVSS V2 None
CVSS V3 None
Description
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
Overview
- CVE ID
- CVE-2024-21622
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-01-03T16:51:25.704Z
- Last Modified Date
- 2024-01-03T16:51:25.704Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx | x_refsource_CONFIRM |
https://github.com/craftcms/cms/pull/13931 | x_refsource_MISC |
https://github.com/craftcms/cms/pull/13932 | x_refsource_MISC |
https://github.com/craftcms/cms/commit/76caf9af07d9964be0fd362772223be6a5f5b6aa | x_refsource_MISC |
https://github.com/craftcms/cms/commit/be81eb653d633833f2ab22510794abb6bb9c0843 | x_refsource_MISC |
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16 | x_refsource_MISC |
https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-21622 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-21622 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 15:03:56 | Added to TrackCVE |