PT-2024-20685 · Tvrock · Tvrock
Published
2024-05-01
·
Updated
2024-11-01
·
CVE-2024-24978
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
TvRock version 0.9t8a
Description
A denial-of-service (DoS) issue exists, where receiving a specially crafted request by a remote attacker or having a user click a specially crafted request may lead to an abnormal end (ABEND). The developer of TvRock is unreachable, and users are advised to consider stopping the use of the affected version.
Recommendations
For TvRock version 0.9t8a, consider stopping its use due to the developer being unreachable and the presence of the denial-of-service vulnerability. As a temporary workaround, consider restricting access to the software to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tvrock