CVE-2024-38485

Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*

History

04 Feb 2025, 16:07

Type Values Removed Values Added
Summary
  • (es) Dell ECS, versiones anteriores a 3.8.0, contiene una vulnerabilidad de inyección de encabezado de host. Un atacante remoto con pocos privilegios podría aprovechar esta vulnerabilidad para activar redirecciones que provoquen la fuga de información confidencial.
References () https://www.dell.com/support/kbdoc/en-us/000256185/dsa-2024-331-security-update-for-dell-ecs-host-header-injection-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000256185/dsa-2024-331-security-update-for-dell-ecs-host-header-injection-vulnerability - Vendor Advisory
CPE cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:*
First Time Dell
Dell elastic Cloud Storage

09 Dec 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-09 15:15

Updated : 2025-02-04 16:07


NVD link : CVE-2024-38485

Mitre link : CVE-2024-38485

CVE.ORG link : CVE-2024-38485


JSON object : View

Products Affected

dell

  • elastic_cloud_storage
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')