CVE-2024-29887
CVSS 3.1 Score 7.4 of 10 (high)
Details
Published Mar 27, 2024
Updated: Mar 28, 2024
CWE ID 295
Summary
CVE-2024-29887 is a vulnerability affecting the `serverpod_client` package used in Serverpod, an app and web server built for the Flutter and Dart ecosystem. This issue bypassed the validation of Transport Layer Security (TLS) certificates on all none web HTTP clients, making them vulnerable to man-in-the-middle (MITM) attacks. An attacker would need to intercept the traffic and hijack the connection to the server to exploit this vulnerability. Upgrading to version 1.2.6 resolves this security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.