CVE-2024-9802

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 10, 2024
Updated: Dec 19, 2024
CWE ID 312

Summary

CVE-2024-9802 refers to a vulnerability in which the conformance validation endpoint is publicly accessible. This endpoint is used to verify the conformance of onboarded services, but anyone can access it. The response may include details about the service, such as available endpoints and Swagger documentation, which could be useful to attackers. Additionally, attackers can use this vulnerability to determine if a specific service is currently operational.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share