CVE-2024-41801

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jul 25, 2024
Updated: Jul 26, 2024
CWE ID 601

Summary

CVE-2024-41801: OpenProject, an open-source project management software, has a vulnerability affecting versions prior to 14.3.0. An attacker could manipulate HOST headers and initiate phishing attacks by redirecting users to remote hosts. This issue impacts default installations running on Apache without additional security measures like mod_security or manually set host names. Version 14.3.0 introduces stronger protections through the HostAuthorization middleware, ensuring hosted links use the built-in hostname. users unable to upgrade immediately should either apply mod_security or manually fix headers in their proxying applications. A patch is also available for older OpenProject versions to opt-in to host header protections.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Openproject
  • OPF OpenProject

Affected Vendors

  • Openproject