CVE-2024-26309: Infoleak
Published Mar 8, 2024
·Updated
Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via an internal URL.
Affected Software
2 affected components
Archer Platform<6.14.0.2.2
Archerirm Archer>=6.3.0.0<6.14.0.2.2
Event History
Mar 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-26309?
CVE-2024-26309 is classified as a sensitive information disclosure vulnerability.
2
How do I fix CVE-2024-26309?
To mitigate CVE-2024-26309, upgrade to Archer Platform version 6.14.0.2.2 or later.
3
Who is affected by CVE-2024-26309?
Users of Archer Platform versions before 6.14.0.2.2 are at risk for CVE-2024-26309.
4
What kind of information can be disclosed in CVE-2024-26309?
CVE-2024-26309 can potentially allow unauthenticated attackers to access sensitive information via an internal URL.
5
What is the workaround for CVE-2024-26309 if unable to update?
If unable to update, consider restricting access to the affected internal URLs as a temporary workaround for CVE-2024-26309.