PT-2024-37595 · Swg · Swg

Published

2024-07-15

·

Updated

2024-07-19

·

CVE-2024-6398

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SWG versions 11.x prior to 11.2.24 SWG versions 12.x prior to 12.2.10
Description An information disclosure issue in SWG allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is considered low because other default security policies, such as URL categorization and GTI, are typically in place to block access to uncategorized or high-risk websites. The extent of the information disclosed depends on how customers have customized their block pages.
Recommendations For SWG versions 11.x prior to 11.2.24, update to version 11.2.24 or later. For SWG versions 12.x prior to 12.2.10, update to version 12.2.10 or later.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-6398

Affected Products

Swg