CVE-2024-29010: XEE
Published May 1, 2024
·Updated
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information.
This issue affects GMS: 9.3.4 and earlier versions.
Affected Software
1 affected component
GMS GMS<9.3.4
Event History
May 1, 2024
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29010?
CVE-2024-29010 is classified as a high-severity vulnerability due to the potential sensitive information disclosure.
2
How do I fix CVE-2024-29010?
To fix CVE-2024-29010, upgrade GMS to version 9.3.5 or later to mitigate the XML external entity injection risk.
3
What versions of GMS are affected by CVE-2024-29010?
CVE-2024-29010 affects GMS versions 9.3.4 and earlier.
4
What type of vulnerability is CVE-2024-29010?
CVE-2024-29010 is an XML external entity (XXE) injection vulnerability.
5
What could be the consequences of CVE-2024-29010?
The consequences of CVE-2024-29010 include potential unauthorized access to sensitive information through XML processing.