CVE-2024-9802
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Oct 10, 2024
Updated: Dec 19, 2024
CWE ID 312
Summary
CVE-2024-9802 refers to a vulnerability in which the conformance validation endpoint is publicly accessible. This endpoint is used to verify the conformance of onboarded services, but anyone can access it. The response may include details about the service, such as available endpoints and Swagger documentation, which could be useful to attackers. Additionally, attackers can use this vulnerability to determine if a specific service is currently operational.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Linux Foundation