CVE-2024-3928: Dromara open-capacity-platform auth-server heapdump information disclosure
A vulnerability was found in Dromara open-capacity-platform 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /actuator/heapdump of the component auth-server. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-261367.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3928?
CVE-2024-3928 has been declared as problematic due to its potential for information disclosure.
What component is affected by CVE-2024-3928?
CVE-2024-3928 affects the auth-server component of the Dromara open-capacity-platform.
How does CVE-2024-3928 lead to information disclosure?
CVE-2024-3928 enables information disclosure through manipulation of the /actuator/heapdump functionality.
How do I fix CVE-2024-3928?
To fix CVE-2024-3928, you should apply any available patches or updates provided by Dromara for the open-capacity-platform.
Which version of Dromara open-capacity-platform is affected by CVE-2024-3928?
CVE-2024-3928 specifically affects version 2.0.1 of the Dromara open-capacity-platform.