CVE-2024-41801
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2024-41801: OpenProject, an open-source project management software, has a vulnerability affecting versions prior to 14.3.0. An attacker could manipulate HOST headers and initiate phishing attacks by redirecting users to remote hosts. This issue impacts default installations running on Apache without additional security measures like mod_security or manually set host names. Version 14.3.0 introduces stronger protections through the HostAuthorization middleware, ensuring hosted links use the built-in hostname. users unable to upgrade immediately should either apply mod_security or manually fix headers in their proxying applications. A patch is also available for older OpenProject versions to opt-in to host header protections.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Openproject
- OPF OpenProject
Affected Vendors
- Openproject