CVE-2024-6741: Openfind Mail2000 - HttpOnly flag bypass
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Openfind Mail2000to a version that resolves this vulnerability.Fixed in 7.0Patch Patch 131 - Upgrade
Upgrade
Openfind Mail2000to a version that resolves this vulnerability.Fixed in 8.0Patch Patch 044
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6741?
CVE-2024-6741 is considered a critical vulnerability due to the potential for unauthenticated remote code execution.
How do I fix CVE-2024-6741?
To fix CVE-2024-6741, update Openfind Mail2000 to the latest version that addresses this vulnerability.
What does CVE-2024-6741 exploit?
CVE-2024-6741 exploits the ability to bypass the HttpOnly flag on session cookies, allowing attackers to access sensitive information.
Which versions of Openfind Mail2000 are affected by CVE-2024-6741?
CVE-2024-6741 affects Openfind Mail2000 versions 7.0 and 8.0.
Can CVE-2024-6741 be exploited remotely?
Yes, CVE-2024-6741 can be exploited remotely by unauthenticated attackers using specific JavaScript code.