CVE-2024-49202
CVSS 3.1 Score 7.6 of 10 (high)
Details
Published Dec 18, 2024
Updated: Dec 21, 2024
CWE ID 276
Summary
CVE-2024-49202 is a vulnerability affecting Keyfactor Command versions prior to 12.5.0. The issue involves incorrect access control, where access tokens are over-permissive. This means that an attacker with unauthorized access to the system could potentially exploit this vulnerability to gain additional privileges. The affected versions include those before 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0. Users are strongly advised to upgrade to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.