CVE-2024-24562

vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx.
Configurations

No configuration.

History

14 Mar 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-14 19:15

Updated : 2024-03-14 20:11


NVD link : CVE-2024-24562

Mitre link : CVE-2024-24562

CVE.ORG link : CVE-2024-24562


JSON object : View

Products Affected

No product.

CWE
CWE-668

Exposure of Resource to Wrong Sphere

CWE-693

Protection Mechanism Failure