CVE-2024-24819
Last modified
CVE-2024-24819 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This is done by automatically adding an element with a CSRF token to any form, unless explicitly disabled, but even if enabled, the CSRF token (sent during a client's submission of a form relying on it) is not validated. This enables attackers to perform changes on behalf of a user which, unknowingly, interacts with a prepared link or website. The version 0.22.0 is available to remedy this issue. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Icinga | Icingaweb2-Module-Incubator | < 0.22.0 |
References
- https://github.com/search?q=gipfl%5CWeb%5CForm%3B&type=codePermissions Required
- https://github.com/search?q=gipfl%5CWeb%5CForm%3B&type=codePermissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-24819?
How severe is CVE-2024-24819?
How do I fix CVE-2024-24819?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-24813Frappe is a full-stack web application framework. Prior to v…7.5
- CVE-2024-24814mod_auth_openidc is an OpenID Certified™ authentication and …7.5
- CVE-2024-24815CKEditor4 is an open source what-you-see-is-what-you-get HTM…6.1
- CVE-2024-24816CKEditor4 is an open source what-you-see-is-what-you-get HTM…6.1
- CVE-2024-24817Discourse Calendar adds the ability to create a dynamic cale…5.3
- CVE-2024-24818EspoCRM is an Open Source Customer Relationship Management s…5.9
- CVE-2024-2482A vulnerability has been found in Surya2Developer Hostel Man…3.7
- CVE-2024-24820Icinga Director is a tool designed to make Icinga 2 configur…8.3
- CVE-2024-24821Composer is a dependency Manager for the PHP language. In af…7.8
- CVE-2024-24822Pimcore's Admin Classic Bundle provides a backend user inter…9.1
- CVE-2024-24823Graylog is a free and open log management platform. Starting…4.4
- CVE-2024-24824Graylog is a free and open log management platform. Starting…8.8
Are you affected by CVE-2024-24819?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
