CVE-2024-6980

July 31, 2024, 12:57 p.m.

None
No Score

Description

A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.

Product(s) Impacted

Product Versions
GravityZone Console
  • before 6.38.1-5

Weaknesses

CWE-209
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.

Date

  • Published: July 31, 2024, 7:15 a.m.
  • Last Modified: July 31, 2024, 12:57 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve-requests@bitdefender.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.