CVE-2024-6980: Verbose error handling issue in GravityZone Update Server proxy service
Published Jul 31, 2024
·Updated
A verbose error handling issue in the proxy service implemented in the GravityZone Update Server allows an attacker to cause a server-side request forgery. This issue only affects GravityZone Console versions before 6.38.1-5 running only on premise.
Affected Software
2 affected components
Bitdefender GravityZone<6.38.1-5
Bitdefender GravityZone Console<6.38.1-5
Remediation
Information
An automatic update to product version 6.38.1-5 fixes the issue.
Event History
Jul 31, 2024
CVE Published
via MITRE·06:58 AM
Data Sourced
via MITRE·06:58 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Feb 22, 57075
Event
via NVD·07:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-6980?
CVE-2024-6980 is classified as a high severity vulnerability due to its potential for server-side request forgery.
2
How do I fix CVE-2024-6980?
To fix CVE-2024-6980, update the GravityZone Console to version 6.38.1-5 or later.
3
What software is affected by CVE-2024-6980?
CVE-2024-6980 affects Bitdefender GravityZone Console versions prior to 6.38.1-5.
4
Can CVE-2024-6980 lead to data breaches?
Yes, CVE-2024-6980 can lead to data breaches by allowing attackers to manipulate server requests.
5
Is CVE-2024-6980 specifically for on-premises installations?
Yes, CVE-2024-6980 affects only on-premises installations of the GravityZone Console.