CRITICAL
Verbose error handling issue in GravityZone Update Server proxy service
Published Jul 31, 2024
9.2
CRITICALCVSS 4.0
EPSS 0.56%
Description
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.
Affected products
-
- Version 0StatusaffectedConstraints<6.38.1-5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bitdefender | GravityZone Update Server | unaffected |
|
- < 6.38.1-5
-
- Version 0StatusaffectedConstraints<6.38.1-5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Bitdefender | Gravityzone | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
An automatic update to product version 6.38.1-5 fixes the issue.
Weaknesses (2)
References (1)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Bitdefender
Published Jul 31, 2024
Updated Jul 31, 2024
Reserved Jul 22, 2024
Link CVE-2024-6980
CISA Vulnrichment
Updated Jul 31, 2024