CVE-2024-38040

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 4, 2024
Updated: Oct 15, 2024
CWE ID 73

Summary

CVE-2024-38040 is a local file inclusion vulnerability affecting Esri Portal for ArcGIS versions 11.2.11.1, 11.1, 11.0, and 10.9.1. This issue allows a remote, unauthenticated attacker to craft malicious URLs, which could potentially grant them access to read sensitive configuration files, posing a significant risk to data privacy. The vulnerability arises from the application's failure to adequately validate and sanitize user input when handling URL requests. Organizations running these vulnerable versions are strongly advised to apply the necessary patches to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Esri Portal for ArcGIS

Affected Vendors

  • Esri