CVE-2024-38645: Notes Station 3
A server-side request forgery (SSRF) vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to read application data.
We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and later
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38645?
CVE-2024-38645 is classified as a server-side request forgery (SSRF) vulnerability which poses a significant risk to affected systems.
How do I fix CVE-2024-38645?
To mitigate CVE-2024-38645, upgrade to Notes Station 3 version 3.9.7 or later, where the vulnerability has been addressed.
Which software is affected by CVE-2024-38645?
CVE-2024-38645 specifically affects Notes Station 3 versions prior to 3.9.7.
What could happen if CVE-2024-38645 is exploited?
If exploited, CVE-2024-38645 could allow remote authenticated attackers to read sensitive application data.
Is CVE-2024-38645 under active exploitation?
There is no public information indicating that CVE-2024-38645 is currently under active exploitation, but it is recommended to apply the fix promptly.