PT-2012-1253 · Mendix · Mendix Runtime

Christopher Panayi

+2

·

Published

2012-11-12

·

Updated

2024-11-15

·

CVE-2024-50313

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mendix Runtime V8 versions Mendix Runtime V9 versions prior to V9.24.29 Mendix Runtime V10 versions prior to V10.16.0 Mendix Runtime V10.6 versions prior to V10.6.15 Mendix Runtime V10.12 versions prior to V10.12.7
Description A race condition vulnerability has been identified in the basic authentication implementation of affected Mendix Runtime applications. This vulnerability could allow unauthenticated remote attackers to circumvent default account lockout measures. The issue is related to synchronization errors when using a shared resource in the basic authentication mechanism, which can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations For Mendix Runtime V8, update to a version that is not affected by this issue. For Mendix Runtime V9 versions prior to V9.24.29, update to V9.24.29 or later. For Mendix Runtime V10 versions prior to V10.16.0, update to V10.16.0 or later. For Mendix Runtime V10.6 versions prior to V10.6.15, update to V10.6.15 or later. For Mendix Runtime V10.12 versions prior to V10.12.7, update to V10.12.7 or later. As a temporary workaround, consider disabling the basic authentication mechanism until a patch is available. Restrict access to affected applications to minimize the risk of exploitation.

Fix

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2024-10318
CVE-2024-50313

Affected Products

Mendix Runtime