PT-2024-37595 · Swg · Swg
Published
2024-07-15
·
Updated
2024-07-19
·
CVE-2024-6398
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SWG versions 11.x prior to 11.2.24
SWG versions 12.x prior to 12.2.10
Description
An information disclosure issue in SWG allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is considered low because other default security policies, such as URL categorization and GTI, are typically in place to block access to uncategorized or high-risk websites. The extent of the information disclosed depends on how customers have customized their block pages.
Recommendations
For SWG versions 11.x prior to 11.2.24, update to version 11.2.24 or later.
For SWG versions 12.x prior to 12.2.10, update to version 12.2.10 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Swg