First published: Tue Mar 05 2024(Updated: )
Improper neutralization of special elements in output (CWE-74) used by the email generation feature of the Command Centre Server could lead to HTML code injection in emails generated by Command Centre. This issue affects: Gallagher Command Centre 9.00 prior to vEL9.00.1774 (MR2), 8.90 prior to vEL8.90.1751 (MR3), 8.80 prior to vEL8.80.1526 (MR4), 8.70 prior to vEL8.70.2526 (MR6), all version of 8.60 and prior.
Credit: disclosures@gallagher.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gallagher Command Centre | <vEL9.00.1774 | |
Gallagher Command Centre | <vEL8.90.1751 | |
Gallagher Command Centre | <vEL8.80.1526 | |
Gallagher Command Centre | <vEL8.70.2526 | |
Gallagher Command Centre | <8.60 | |
Gallagher Command Centre | <=8.60 | |
Gallagher Command Centre | >=8.70<8.70.2526 | |
Gallagher Command Centre | >=8.80<8.80.1526 | |
Gallagher Command Centre | >=8.90<8.90.1751 | |
Gallagher Command Centre | >=9.00<9.00.1774 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-21838 is classified as a medium risk due to the potential for HTML code injection in emails.
To fix CVE-2024-21838, upgrade Gallagher Command Centre to version vEL9.00.1774 or later.
CVE-2024-21838 affects Gallagher Command Centre versions prior to vEL9.00.1774, as well as several earlier versions down to 8.60.
CVE-2024-21838 is an improper neutralization of special elements in output, specifically related to HTML code injection.
There are currently no documented workarounds for CVE-2024-21838 other than upgrading to a fixed version.