CVE-2024-24562

vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx.
Configurations

No configuration.

History

21 Nov 2024, 08:59

Type Values Removed Values Added
References () https://github.com/vantage6/vantage6-UI/commit/68dfa661415182da0e5717bd58db3d00aedcbd2e - () https://github.com/vantage6/vantage6-UI/commit/68dfa661415182da0e5717bd58db3d00aedcbd2e -
References () https://github.com/vantage6/vantage6-UI/security/advisories/GHSA-gwq3-pvwq-4c9w - () https://github.com/vantage6/vantage6-UI/security/advisories/GHSA-gwq3-pvwq-4c9w -
Summary
  • (es) vantage6-UI es la interfaz de usuario oficial para el servidor vantage6. En las versiones afectadas, no se establecen varios encabezados de seguridad. Este problema se solucionó en el commit `68dfa6614`, que se espera que se incluya en futuras versiones. Se recomienda a los usuarios que actualicen cuando se realice una nueva versión. Si bien no hay una ruta de actualización disponible, los usuarios pueden modificar la compilación de la imagen de la ventana acoplable para insertar los encabezados en nginx.

14 Mar 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-14 19:15

Updated : 2024-11-21 08:59


NVD link : CVE-2024-24562

Mitre link : CVE-2024-24562

CVE.ORG link : CVE-2024-24562


JSON object : View

Products Affected

No product.

CWE
CWE-668

Exposure of Resource to Wrong Sphere

CWE-693

Protection Mechanism Failure