CVE-2024-58320: Kentico Xperience <= 13.0.159 Authentication Information Disclosure
An information disclosure vulnerability in Kentico Xperience allows public users to access sensitive administration interface hostname details during authentication. Attackers can retrieve confidential hostname configuration information through a public endpoint, potentially exposing internal network details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-58320?
CVE-2024-58320 is classified as an information disclosure vulnerability.
How do I fix CVE-2024-58320?
To fix CVE-2024-58320, ensure you apply the latest security patches provided by Kentico for Xperience versions up to 13.0.159.
Who is affected by CVE-2024-58320?
CVE-2024-58320 affects users of Kentico Xperience versions up to and including 13.0.159.
What type of information can be disclosed due to CVE-2024-58320?
CVE-2024-58320 allows public users to access sensitive administration interface hostname details during authentication.
Is authentication compromised due to CVE-2024-58320?
While authentication itself is not compromised, sensitive hostname configuration information can be accessed, which poses a security risk.