CVE-2024-38037: BUG-000167983 - Unvalidated redirect in Portal for ArcGIS
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and 10.9.1 that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
Other sources
There is an unvalidated redirect vulnerability in Esri Portal for ArcGIS 11.0 and below that may allow a remote, unauthenticated attacker to craft a URL that could redirect a victim to an arbitrary website, simplifying phishing attacks.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38037?
CVE-2024-38037 has been assessed as a high severity vulnerability due to its potential for phishing attacks.
How do I fix CVE-2024-38037?
To fix CVE-2024-38037, upgrade to the latest versions of Esri Portal for ArcGIS and apply any available security patches.
What types of attacks can CVE-2024-38037 facilitate?
CVE-2024-38037 can facilitate unvalidated redirect attacks, which can be leveraged for phishing.
Which versions of Esri Portal for ArcGIS are affected by CVE-2024-38037?
CVE-2024-38037 affects Esri Portal for ArcGIS versions 10.9.1 and 11.0.
Is it possible for attackers to exploit CVE-2024-38037 remotely?
Yes, CVE-2024-38037 can be exploited remotely by unauthenticated attackers.