PT-2012-1253 · Mendix · Mendix Runtime
Christopher Panayi
+2
·
Published
2012-11-12
·
Updated
2024-11-15
·
CVE-2024-50313
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Mendix Runtime V8 versions
Mendix Runtime V9 versions prior to V9.24.29
Mendix Runtime V10 versions prior to V10.16.0
Mendix Runtime V10.6 versions prior to V10.6.15
Mendix Runtime V10.12 versions prior to V10.12.7
Description
A race condition vulnerability has been identified in the basic authentication implementation of affected Mendix Runtime applications. This vulnerability could allow unauthenticated remote attackers to circumvent default account lockout measures. The issue is related to synchronization errors when using a shared resource in the basic authentication mechanism, which can be exploited by a remote attacker to bypass existing security restrictions.
Recommendations
For Mendix Runtime V8, update to a version that is not affected by this issue.
For Mendix Runtime V9 versions prior to V9.24.29, update to V9.24.29 or later.
For Mendix Runtime V10 versions prior to V10.16.0, update to V10.16.0 or later.
For Mendix Runtime V10.6 versions prior to V10.6.15, update to V10.6.15 or later.
For Mendix Runtime V10.12 versions prior to V10.12.7, update to V10.12.7 or later.
As a temporary workaround, consider disabling the basic authentication mechanism until a patch is available. Restrict access to affected applications to minimize the risk of exploitation.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mendix Runtime