CVE-2024-38037

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Oct 4, 2024
Updated: Oct 15, 2024
CWE ID 601

Summary

CVE-2024-38037 is a newly disclosed vulnerability affecting Esri Portal for ArcGIS versions 11.0 and 10.9.1. This issue involves an unvalidated redirect, enabling a remote, unauthenticated attacker to craft malicious URLs. If successful, the victim would be redirected to an arbitrary website, potentially falling prey to phishing attacks. This vulnerability poses a significant risk, particularly in enterprise environments where users may trust links within the portal. Organizations utilizing these versions of Esri Portal for ArcGIS are strongly encouraged to apply the forthcoming patches to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Esri Portal for ArcGIS
  • Portal for ArcGIS

Affected Vendors

  • Esri