CVE-2024-34803: WordPress Fastly plugin <= 1.2.25 - Broken Access Control vulnerability
Published Jun 3, 2024
·Updated
Missing Authorization vulnerability in Fastly.This issue affects Fastly: from n/a through 1.2.25.
Affected Software
2 affected components
Fastly Fastly<=1.2.25
WordPress Fastly plugin<=1.2.25
Remediation
Information
Update to 1.2.26 or a higher version.
Event History
Jun 3, 2024
CVE Published
via MITRE·10:18 AM
Data Sourced
via MITRE·10:18 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-34803?
CVE-2024-34803 is considered a high severity vulnerability due to its missing authorization flaw.
2
What software versions are affected by CVE-2024-34803?
CVE-2024-34803 affects Fastly up to version 1.2.25 and the WordPress Fastly plugin up to version 1.2.25.
3
How do I fix CVE-2024-34803?
To fix CVE-2024-34803, update Fastly or the WordPress Fastly plugin to the latest version where the vulnerability is patched.
4
What type of vulnerability is CVE-2024-34803?
CVE-2024-34803 is a missing authorization vulnerability, which can potentially allow unauthorized access to restricted resources.
5
Who is the vendor for CVE-2024-34803?
The vendor for CVE-2024-34803 is Fastly, known for its content delivery network services.