CVE-2024-41668: cBioPortal Proxy Endpoint Vulnerabliity
The cBioPortal for Cancer Genomics provides visualization, analysis, and download of large-scale cancer genomics data sets. When running a publicly exposed proxy endpoint without authentication, cBioPortal could allow someone to perform a Server Side Request Forgery (SSRF) attack. Logged in users could do the same on private instances. A fix has been released in version 6.0.12. As a workaround, one might be able to disable /proxy endpoint entirely via, for example, nginx.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41668?
CVE-2024-41668 is classified as a high severity vulnerability due to its potential for SSRF attacks when the application is publicly exposed.
How do I fix CVE-2024-41668?
To fix CVE-2024-41668, ensure that the proxy endpoint is secured with proper authentication mechanisms.
What software versions are affected by CVE-2024-41668?
CVE-2024-41668 affects cBioPortal versions prior to 6.0.12.
What kind of attack does CVE-2024-41668 allow?
CVE-2024-41668 allows for Server Side Request Forgery (SSRF) attacks.
Is CVE-2024-41668 a local or remote vulnerability?
CVE-2024-41668 is a remote vulnerability as it can be exploited via a publicly accessible endpoint.