CVE-2024-28215: High severity ngrinder vulnerability
nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28215?
The severity of CVE-2024-28215 is currently classified as medium due to its potential for information disclosure and server-side request forgery.
How do I fix CVE-2024-28215?
To fix CVE-2024-28215, upgrade nGrinder to version 3.5.9 or later, which includes the necessary access controls.
What implications does CVE-2024-28215 have on my system?
CVE-2024-28215 could allow unauthorized users to manipulate webhook configurations, leading to possible data leakage and abuse.
Which versions of nGrinder are affected by CVE-2024-28215?
CVE-2024-28215 affects nGrinder versions prior to 3.5.9.
Is there a way to mitigate CVE-2024-28215 if I cannot upgrade?
If an upgrade is not possible, consider implementing strict network controls and monitoring to limit access to the nGrinder instance.