CVE-2024-46412: Medium severity REBUILD REBUILD vulnerability
Published Aug 25, 2025
·Updated
Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass authentication via a crafted GET request sent to /commons/ip-location.
Affected Software
1 affected component
REBUILD REBUILD
Event History
Aug 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-46412?
The severity of CVE-2024-46412 has not been officially assigned, but it allows attackers to bypass authentication, indicating a potentially high risk.
2
How do I fix CVE-2024-46412?
To fix CVE-2024-46412, update to the latest version of Rebuild or ensure proper access controls are implemented for the prehandle function.
3
What type of attack can exploit CVE-2024-46412?
CVE-2024-46412 can be exploited through crafted GET requests sent to the /commons/ip-location endpoint.
4
Which software versions are affected by CVE-2024-46412?
CVE-2024-46412 affects Rebuild version 3.7.7.
5
Is CVE-2024-46412 a remote vulnerability?
Yes, CVE-2024-46412 can be exploited remotely due to its nature of bypassing authentication via crafted requests.