CVE-2024-53276

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Dec 23, 2024
Updated: Dec 24, 2024
CWE ID 942

Summary

CVE-2024-53276 is a vulnerability affecting Home-Gallery.org, a self-hosted open-source web gallery. In versions 1.15.0 and earlier, an open CORS policy in app.js exposes the gallery to potential attacks. An attacker can make cross-site requests to home-gallery, enabling them to view images and access any endpoint on the gallery. This vulnerability could potentially allow an attacker to view preview images and gain unauthorized access to any static files or endpoints that may contain sensitive information, if introduced in the future. Home-gallery is generally safe from cross-site requests due to most pages requiring JavaScript, but the vulnerability can bypass this protection. It is recommended that users update to the latest version of Home-Gallery to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share