CVE-2024-29010
Last modified
CVE-2024-29010 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions. . EPSS estimates a 0.62% chance of exploitation in the next 30 days.
Description
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-29010?
How severe is CVE-2024-29010?
How do I fix CVE-2024-29010?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-29004The SolarWinds Platform was determined to be affected by a s…4.3
- CVE-2024-29006By default the CloudStack management server honours the x-fo…9.8
- CVE-2024-29007The CloudStack management server and secondary storage VM co…7.3
- CVE-2024-29008A problem has been identified in the CloudStack additional V…6.4
- CVE-2024-29009Cross-site request forgery (CSRF) vulnerability in easy-popu…6.1
- CVE-2024-2901A vulnerability has been found in Tenda AC7 15.03.06.44 and …8.8
- CVE-2024-29011Use of hard-coded password in the GMS ECM endpoint leading t…7.5
- CVE-2024-29012Stack-based buffer overflow vulnerability in the SonicOS HTT…7.5
- CVE-2024-29013Heap-based buffer overflow vulnerability in the SonicOS SSL-…6.5
- CVE-2024-29014Vulnerability in SonicWall SMA100 NetExtender Windows (32 an…8.8
- CVE-2024-29015Uncontrolled search path in some Intel(R) VTune(TM) Profiler…7.8
- CVE-2024-29018Moby is an open source container framework that is a key com…7.5
Are you affected by CVE-2024-29010?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
