CVE-2024-2291

In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
References () https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024 - () https://community.progress.com/s/article/MOVEit-Transfer-Service-Pack-March-2024 -
References () https://www.progress.com/moveit - () https://www.progress.com/moveit -
Summary
  • (es) Se ha descubierto una vulnerabilidad de omisión de registro en las versiones de MOVEit Transfer publicadas antes de 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4). Un usuario autenticado podría manipular una solicitud para omitir el mecanismo de registro dentro de la aplicación web, lo que da como resultado que la actividad del usuario no se registre correctamente.

20 Mar 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-20 15:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2291

Mitre link : CVE-2024-2291

CVE.ORG link : CVE-2024-2291


JSON object : View

Products Affected

No product.

CWE
CWE-778

Insufficient Logging