« Volver al listado

CVE-2024-2465

Estado: AnalizadaAlta (7.1)—

Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-2465",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-2465",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-01T19:53:07.061994Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cvd@cert.pl",
      "affectedData": [
        {
          "vendor": "CDeX PSA",
          "product": "CDeX",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "5.7.1"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-03-21T15:16:54.553",
  "references": [
    {
      "url": "https://cdex.cloud/",
      "tags": [
        "Product"
      ],
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cert.pl/en/posts/2024/03/CVE-2024-2463/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cert.pl/posts/2024/03/CVE-2024-2463/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cvd@cert.pl"
    },
    {
      "url": "https://cdex.cloud/",
      "tags": [
        "Product"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cert.pl/en/posts/2024/03/CVE-2024-2463/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cert.pl/posts/2024/03/CVE-2024-2463/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cvd@cert.pl",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.\n\n"
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de redirección abierta en la aplicación CDeX permite redirigir a los usuarios a sitios web arbitrarios a través de una URL especialmente manipulada. Este problema afecta a las versiones de la aplicación CDeX hasta la 5.7.1."
    }
  ],
  "lastModified": "2026-06-17T07:24:35.407",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cdex:cdex:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B0727A25-ACE5-4E39-A68F-84974E7CE0BA",
              "versionEndIncluding": "5.71"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cvd@cert.pl"
}