CVE-2024-54840

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.

Severity
Medium 4.2
CVSS 3.1
Exploited
Not listed
EPSS
0.002
5.4th percentile
Discovered by
Not disclosed
Published
Feb 3, 2025
Assigned by mitre

Description

PVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues that can contribute to Host header injection.

Weakness: CWE-348

Affected products

Vendor Product Category Matched by
Palo Alto Networks CyberArk Privileged Access Manager Identity / IAM / MFA affected-vendor
Vendor-reported products (1)
  • CyberArk · Privileged Access Manager

Something wrong here?