CVE-2024-33500: High severity Mendix Mendix 10 vulnerability
A vulnerability has been identified in Mendix Applications using Mendix 10 (All versions < V10.11.0), Mendix Applications using Mendix 10 (V10.6) (All versions < V10.6.9), Mendix Applications using Mendix 9 (All versions >= V9.3.0 < V9.24.22). Affected applications could allow users with the capability to manage a role to elevate the access rights of users with that role. Successful exploitation requires to guess the id of a target role which contains the elevated access rights.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33500?
CVE-2024-33500 is considered a critical vulnerability affecting specific versions of Mendix Applications.
How do I fix CVE-2024-33500?
To fix CVE-2024-33500, upgrade your Mendix Applications to version 10.11.0 or version 9.24.22 and above.
Which versions of Mendix Applications are affected by CVE-2024-33500?
CVE-2024-33500 affects Mendix 10 versions below 10.11.0, Mendix 10 (V10.6) below 10.6.9, and Mendix 9 versions between 9.3.0 and 9.24.22.
What types of vulnerabilities does CVE-2024-33500 include?
CVE-2024-33500 includes vulnerabilities that could allow unauthorized users to access sensitive features of Mendix Applications.
Is CVE-2024-33500 reversible after applying the patch?
Once patched to mitigate CVE-2024-33500, it is recommended to test the applications to ensure that normal functionality is restored.