CVE Vulnerabilities

CVE-2024-34524

Authentication Bypass Using an Alternate Path or Channel

Published: May 06, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In XLANG OpenAgents through fe73ac4, the allowed_file protection mechanism can be bypassed by using an incorrect file extension for the nature of the file content.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References