PT-2024-36795 · Unknown · Onyxia-Api

Nicolst

·

Published

2024-12-20

·

Updated

2024-12-20

·

CVE-2024-56333

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Onyxia-API versions prior to 2.8.2 Onyxia-API versions prior to 3.1.1 Onyxia-API versions prior to 4.2.0
Description This issue allows authenticated users to remotely execute code within the Onyxia-API, potentially leading to unauthorized access to other user environments and denial of service attacks.
Recommendations For versions prior to 2.8.2, upgrade to version 2.8.2 or later. For versions prior to 3.1.1, upgrade to version 3.1.1 or later. For versions prior to 4.2.0, upgrade to version 4.2.0 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-56333
GHSA-QMCW-H4F9-J3H3

Affected Products

Onyxia-Api