Vulnerability Description
The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FKAoOUA
- https://deneyed.com/blog/avalara/
- https://appexchange.salesforce.com/appxListingDetail?listingId=a0N3A00000FKAoOUA
- https://deneyed.com/blog/avalara/
FAQ
What is CVE-2024-38453?
CVE-2024-38453 is a vulnerability with a CVSS score of 7.5 (HIGH). The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
How severe is CVE-2024-38453?
CVE-2024-38453 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38453?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.