Vulnerability Description
PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cyberark | Privileged Access Manager | < 14.4 |
Related Weaknesses (CWE)
References
- https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-wRelease Notes
- https://gist.github.com/Hurdano/8244855ef8ec364fd98a2693de6e30c5Third Party Advisory
FAQ
What is CVE-2024-54840?
CVE-2024-54840 is a vulnerability with a CVSS score of 4.2 (MEDIUM). PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.
How severe is CVE-2024-54840?
CVE-2024-54840 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-54840?
Check the references section above for vendor advisories and patch information. Affected products include: Cyberark Privileged Access Manager.