PT-2024-29495 · Unknown · Cbioportal

Boonking1220

·

Published

2024-07-23

·

Updated

2024-07-24

·

CVE-2024-41668

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions cBioPortal versions prior to 6.0.12
Description The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, cBioPortal could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances.
Recommendations For versions prior to 6.0.12, update to version 6.0.12 to resolve the issue. As a temporary workaround, consider disabling the "/proxy" endpoint entirely via, for example, nginx.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-41668
GHSA-9H44-R3C3-Q7RM

Affected Products

Cbioportal