CVE-2024-28216: Medium severity ngrinder vulnerability
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28216?
CVE-2024-28216 is categorized as a moderate severity vulnerability due to potential information disclosure and limited Server-Side Request Forgery risks.
How do I fix CVE-2024-28216?
To fix CVE-2024-28216, upgrade nGrinder to version 3.5.9 or later to implement necessary access controls.
What types of attacks can exploit CVE-2024-28216?
CVE-2024-28216 can be exploited for information disclosure and could allow attackers to perform limited Server-Side Request Forgery.
Which versions of nGrinder are affected by CVE-2024-28216?
CVE-2024-28216 affects all versions of nGrinder before 3.5.9.
What are the potential impacts of CVE-2024-28216 on my system?
The potential impacts of CVE-2024-28216 include unauthorized access to webhook request results, leading to information leaks.