CVE-2024-54840: Medium severity cyberark privileged access manager vulnerability
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54840?
CVE-2024-54840 is classified as a medium severity vulnerability due to its potential to enable Host header injection.
How do I fix CVE-2024-54840?
To fix CVE-2024-54840, upgrade your CyberArk Privileged Access Manager Self-Hosted to version 14.4 or later.
What is Host header injection as related to CVE-2024-54840?
Host header injection is a vulnerability that can allow an attacker to manipulate the Host header and potentially perform unauthorized actions.
Which versions of CyberArk Privileged Access Manager are affected by CVE-2024-54840?
CVE-2024-54840 affects all versions of CyberArk Privileged Access Manager Self-Hosted prior to 14.4.
Is there a known exploit for CVE-2024-54840?
As of now, there are no known exploits published for CVE-2024-54840, but it is recommended to address the vulnerability promptly.