PT-2024-29888 · Galaxy · Galaxy

Davelopez

·

Published

2024-09-20

·

Updated

2025-08-15

·

CVE-2024-42351

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Galaxy versions prior to release 21.05
Description Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering.
Recommendations For Galaxy versions prior to release 21.05, users are advised to upgrade to a newer version that includes the patch for this issue. At the moment, there is no information about other mitigation measures.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-42351
GHSA-5639-CMPH-9J4V

Affected Products

Galaxy