216.73.217.98

CVE-2024-45187

· Published 23/08/2024 19:15 · Modified 26/08/2024 12:47

Labels: CVE-2024-45187 2024-08-23CVE-2024-45187CWE-266[email protected]

Essential information

Published
23/08/2024 19:15
Modified
26/08/2024 12:47
Author
Creator
CVSS
7.1 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References