CVE-2024-23734: CSRF
Published Apr 10, 2024
·Updated
Cross Site Request Forgery vulnerability in in the upload functionality of the User Profile pages in savignano S/Notify before 2.0.1 for Bitbucket allow attackers to replace S/MIME certificate or PGP keys for arbitrary users via crafted link.
Affected Software
3 affected components
savignano S/Notify<2.0.1
Atlassian Bitbucket
savignano S-notify Bitbucket<2.0.1
Event History
Apr 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23734?
CVE-2024-23734 is considered a high severity vulnerability due to its potential impact on user data integrity.
2
How do I fix CVE-2024-23734?
To remediate CVE-2024-23734, update Savignano S/Notify to version 2.0.1 or later.
3
Who is affected by CVE-2024-23734?
Users of Savignano S/Notify before version 2.0.1 and Atlassian Bitbucket are affected by CVE-2024-23734.
4
What type of vulnerability is CVE-2024-23734?
CVE-2024-23734 is a Cross Site Request Forgery (CSRF) vulnerability.
5
What can attackers do with CVE-2024-23734?
Attackers exploiting CVE-2024-23734 can replace S/MIME certificates or PGP keys for any user by using a crafted link.