First published: Mon Jan 06 2025(Updated: )
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure of Artifactory API keys. This vulnerability allows users to publish code to private packages or repositories under the name of the organization.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Controller | <=11.1.0 | |
IBM Cognos Controller | <=11.0.0 - 11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-28778 has been rated as a critical vulnerability due to the potential exposure of sensitive API keys.
To mitigate CVE-2024-28778, update IBM Cognos Controller to versions 11.0.2 or later, or IBM Controller to version 11.1.1 or later.
CVE-2024-28778 affects IBM Cognos Controller versions 11.0.0 through 11.0.1 and IBM Controller version 11.1.0.
The impact of CVE-2024-28778 includes unauthorized code publishing to private repositories, which could lead to reputation damage and data compromise.
As a temporary workaround for CVE-2024-28778, organizations should restrict access to the Artifactory API until an upgrade can be performed.