CVE-2024-24562
CVSS V2 None
CVSS V3 None
Description
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx.
Overview
- CVE ID
- CVE-2024-24562
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-03-14T18:52:31.109Z
- Last Modified Date
- 2024-06-04T17:43:20.387Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/vantage6/vantage6-UI/security/advisories/GHSA-gwq3-pvwq-4c9w | x_refsource_CONFIRM |
https://github.com/vantage6/vantage6-UI/commit/68dfa661415182da0e5717bd58db3d00aedcbd2e | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-24562 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24562 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 04:04:32 | Added to TrackCVE |