PT-2024-20685 · Tvrock · Tvrock

Published

2024-05-01

·

Updated

2024-11-01

·

CVE-2024-24978

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions TvRock version 0.9t8a
Description A denial-of-service (DoS) issue exists, where receiving a specially crafted request by a remote attacker or having a user click a specially crafted request may lead to an abnormal end (ABEND). The developer of TvRock is unreachable, and users are advised to consider stopping the use of the affected version.
Recommendations For TvRock version 0.9t8a, consider stopping its use due to the developer being unreachable and the presence of the denial-of-service vulnerability. As a temporary workaround, consider restricting access to the software to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Related Identifiers

CVE-2024-24978

Affected Products

Tvrock