First published: Mon Feb 03 2025(Updated: )
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CyberArk Privileged Access Manager | <14.4 | |
Broadcom Privileged Access Manager | <14.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54840 is classified as a medium severity vulnerability due to its potential to enable Host header injection.
To fix CVE-2024-54840, upgrade your CyberArk Privileged Access Manager Self-Hosted to version 14.4 or later.
Host header injection is a vulnerability that can allow an attacker to manipulate the Host header and potentially perform unauthorized actions.
CVE-2024-54840 affects all versions of CyberArk Privileged Access Manager Self-Hosted prior to 14.4.
As of now, there are no known exploits published for CVE-2024-54840, but it is recommended to address the vulnerability promptly.