PT-2024-25421 · Portainer+2 · Portainer+2

Jtraxy

·

Published

2024-10-01

·

Updated

2024-12-04

·

CVE-2024-33662

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Portainer versions prior to 2.20.2
Description The issue is related to the improper use of an encryption algorithm in the AesEncrypt function. This flaw can lead to weak encryption. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For versions prior to 2.20.2, upgrade to version 2.20.2 to address this risk. As a temporary workaround, consider restricting the use of the AesEncrypt function until the issue is resolved.

Exploit

Fix

DoS

Use of a Broken Cryptographic Algorithm

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

CVE-2024-33662
GHSA-9MJW-79R6-C9M8
GO-2024-3172
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14447-1
OPENSUSE-SU-2024_3911-1
SUSE-SU-2024:3911-1

Affected Products

Portainer
Red Os
Suse