CVE-2024-24562
vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers are not set. This issue has been addressed in commit `68dfa6614` which is expected to be included in future releases. Users are advised to upgrade when a new release is made. While an upgrade path is not available users may modify the docker image build to insert the headers into nginx.
- Affected products
- Docker, Nginx, Vantage6-Ui
- vantage6 vantage6-ui
- ≤ 4.2.0
- Fix
- Available
- CVSS 3.1
- 5.4 MEDIUM
- EPSS
- 0.3% (28th percentile)
- Weakness
- CWE-668, CWE-693
- NVD status
- Analyzed
- Published
- 2024-03-14
CVE-2024-24562 at NVD
No indexed exploits for CVE-2024-24562 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-24562 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.