PT-2024-25945 · Syracuse · Avantra Server
Published
2024-05-05
·
Updated
2024-07-03
·
CVE-2024-34519
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Avantra Server versions 24.0.0 through 24.0.6
Avantra Server versions 24.1.0 through 24.1.0
Description
The issue concerns the mishandling of dashboard security. If a user can create a dashboard with an auto-login user, data disclosure may occur. Access control can be bypassed when there is a shared dashboard and its auto-login user has privileges that a dashboard visitor should not have.
Recommendations
For Avantra Server versions 24.0.0 through 24.0.6, update to version 24.0.7 or later.
For Avantra Server versions 24.1.0 through 24.1.0, update to version 24.1.1 or later.
As a temporary workaround, consider restricting access to shared dashboards with auto-login users to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avantra Server