CVE-2024-22200: vantage6-UI docker image leaks software version information
vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular application. This vulnerability was patched in 4.2.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vantage6-UI docker imageto a version that resolves this vulnerability.Fixed in 4.2.0 - Compensating control
Mitigate by running the UI as an angular application instead of using the vantage6-UI docker image that leaks the nginx version.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22200?
CVE-2024-22200 is of moderate severity due to information disclosure from the nginx version leak.
How do I fix CVE-2024-22200?
To fix CVE-2024-22200, upgrade the vantage6-UI to version 4.2.0 or later.
What should I do if I cannot upgrade to version 4.2.0 for CVE-2024-22200?
If you cannot upgrade, you can mitigate CVE-2024-22200 by running the UI as an Angular application.
What does CVE-2024-22200 affect?
CVE-2024-22200 affects the vantage6-UI prior to version 4.2.0.
Is there a patch available for CVE-2024-22200?
Yes, a patch for CVE-2024-22200 is available in version 4.2.0 of the vantage6-UI.