CVE-2024-21676
Apache Apache Kafka Deserialization Vulnerability
Description
Rejected reason: This CVE's publication may have been a false positive or a mistake. As a result, we have rejected this record.
INFO
Published Date :
April 16, 2024, 5:15 p.m.
Last Modified :
April 18, 2024, 5:15 p.m.
Source :
[email protected]
Remotely Exploitable :
Yes !
Impact Score :
5.9
Exploitability Score :
2.8
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2024-21676
vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2024-21676
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Rejected by [email protected]
Apr. 18, 2024
Action Type Old Value New Value -
CVE Modified by [email protected]
Apr. 18, 2024
Action Type Old Value New Value Changed Description This High severity Injection vulnerability was introduced in versions 7.3.0 of Confluence Data Center. This Injection vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 8.5: Upgrade to a release greater than or equal to 8.5.8 See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was discovered by l3yx and reported via our Bug Bounty program Rejected reason: This CVE's publication may have been a false positive or a mistake. As a result, we have rejected this record. Removed Reference Atlassian https://jira.atlassian.com/rest/api/2/issue/2005000 Removed CVSS V3 Atlassian AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H -
CVE Translated by [email protected]
Apr. 18, 2024
Action Type Old Value New Value Removed Translation Title: Confluence Data Center Description: Esta vulnerabilidad de inyección de alta gravedad se introdujo en las versiones 7.3.0 de Confluence Data Center. Esta vulnerabilidad de inyección, con una puntuación CVSS de 8,8, permite a un atacante no autenticado modificar las acciones tomadas por una llamada al sistema, lo que tiene un alto impacto en la confidencialidad, un alto impacto en la integridad, un alto impacto en la disponibilidad y requiere la interacción del usuario. Atlassian recomienda que los clientes de Confluence Data Center actualicen a la última versión; si no pueden hacerlo, actualicen su instancia a una de las versiones fijas admitidas especificadas: Confluence Data Center 8.5: actualice a una versión mayor o igual a 8.5.8 Consulte las notas de la versión (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). Puede descargar la última versión de Confluence Data Center desde el centro de descargas (https://www.atlassian.com/software/confluence/download-archives). Esta vulnerabilidad fue descubierta por l3yx y reportada a través de nuestro programa Bug Bounty. -
CVE Received by [email protected]
Apr. 16, 2024
Action Type Old Value New Value Added Description This High severity Injection vulnerability was introduced in versions 7.3.0 of Confluence Data Center. This Injection vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to modify the actions taken by a system call which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 8.5: Upgrade to a release greater than or equal to 8.5.8 See the release notes (https://confluence.atlassian.com/doc/confluence-release-notes-327.html). You can download the latest version of Confluence Data Center from the download center (https://www.atlassian.com/software/confluence/download-archives). This vulnerability was discovered by l3yx and reported via our Bug Bounty program Added Reference Atlassian https://jira.atlassian.com/rest/api/2/issue/2005000 [No types assigned] Added CVSS V3 Atlassian AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2024-21676
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2024-21676
weaknesses.