First published: Wed Aug 14 2024(Updated: )
A command injection issue in Palo Alto Networks Cortex XSOAR CommonScripts Pack allows an unauthenticated attacker to execute arbitrary commands within the context of an integration container.
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Paloaltonetworks Cortex Xsoar Commonscripts | <1.12.33 |
This issue is fixed in Cortex XSOAR CommonScripts 1.12.33 and all later versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5914 has a high severity due to the ability for unauthenticated attackers to execute arbitrary commands.
To mitigate CVE-2024-5914, update the Palo Alto Networks Cortex XSOAR CommonScripts Pack to version 1.12.33 or later.
CVE-2024-5914 affects versions of the Palo Alto Networks Cortex XSOAR CommonScripts Pack up to but not including version 1.12.33.
CVE-2024-5914 is classified as a command injection vulnerability.
CVE-2024-5914 can be exploited by unauthenticated attackers.