PT-2024-20453 · Docker+2 · Docker+2

Bartvanb

·

Published

2024-03-14

·

Updated

2025-08-06

·

CVE-2024-24562

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions vantage6-UI (affected versions not specified)
Description The issue is related to the absence of certain security headers in the vantage6-UI, which is the official user interface for the vantage6 server. This problem has been addressed in a specific commit, and users are advised to upgrade when a new release is made. As a temporary measure, users can modify the Docker image build to insert the necessary headers into nginx.
Recommendations For all affected versions, users are advised to upgrade to a newer version when it is released. As a temporary workaround, consider modifying the Docker image build to insert the necessary security headers into nginx.

Exploit

Fix

Protection Mechanism Failure

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2024-24562
GHSA-GWQ3-PVWQ-4C9W

Affected Products

Docker
Nginx
Vantage6-Ui