Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
References
Configurations
History
No history.
Information
Published : 2024-12-09 15:15
Updated : 2025-02-04 16:07
NVD link : CVE-2024-38485
Mitre link : CVE-2024-38485
CVE.ORG link : CVE-2024-38485
JSON object : View
Products Affected
dell
- elastic_cloud_storage
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
