CVE Vulnerabilities

CVE-2024-27185

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Aug 20, 2024 | Modified: Aug 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The pagination class includes arbitrary parameters in links, leading to cache poisoning attack vectors.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

References