Vulnerability Description
The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Articatech | Artica Proxy | 4.50.000000 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2024/Mar/12ExploitMailing List
- https://korelogic.com/Resources/Advisories/KL-001-2024-002.txtExploitThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/12ExploitMailing List
- https://korelogic.com/Resources/Advisories/KL-001-2024-002.txtExploitThird Party Advisory
FAQ
What is CVE-2024-2054?
CVE-2024-2054 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Artica-Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
How severe is CVE-2024-2054?
CVE-2024-2054 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-2054?
Check the references section above for vendor advisories and patch information. Affected products include: Articatech Artica Proxy.