PT-2024-25945 · Syracuse · Avantra Server

Published

2024-05-05

·

Updated

2024-07-03

·

CVE-2024-34519

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Avantra Server versions 24.0.0 through 24.0.6 Avantra Server versions 24.1.0 through 24.1.0
Description The issue concerns the mishandling of dashboard security. If a user can create a dashboard with an auto-login user, data disclosure may occur. Access control can be bypassed when there is a shared dashboard and its auto-login user has privileges that a dashboard visitor should not have.
Recommendations For Avantra Server versions 24.0.0 through 24.0.6, update to version 24.0.7 or later. For Avantra Server versions 24.1.0 through 24.1.0, update to version 24.1.1 or later. As a temporary workaround, consider restricting access to shared dashboards with auto-login users to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-34519

Affected Products

Avantra Server