CVE-2024-21622
Estado: ModificadaAlta (8.8)—
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.59%
- Percentil entre todas las CVEs puntuadas: 46
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-269
- NVD-CWE-noinfo
Referencias
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16
- https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16
- https://github.com/craftcms/cms/commit/76caf9af07d9964be0fd362772223be6a5f5b6aa
- https://github.com/craftcms/cms/commit/be81eb653d633833f2ab22510794abb6bb9c0843
- https://github.com/craftcms/cms/pull/13931
- https://github.com/craftcms/cms/pull/13932
- https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx
- https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16
- https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16
- https://github.com/craftcms/cms/commit/76caf9af07d9964be0fd362772223be6a5f5b6aa
- https://github.com/craftcms/cms/commit/be81eb653d633833f2ab22510794abb6bb9c0843
- https://github.com/craftcms/cms/pull/13931
- https://github.com/craftcms/cms/pull/13932
- https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-21622",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-21622",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-01-08T17:11:55.447281Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "craftcms",
"product": "cms",
"versions": [
{
"status": "affected",
"version": ">= 4.0.0-RC1, < 4.5.11"
},
{
"status": "affected",
"version": ">= 3.0.0, < 3.9.6"
}
]
}
]
}
],
"published": "2024-01-03T17:15:12.330",
"references": [
{
"url": "https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16",
"tags": [
"Release Notes"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/commit/76caf9af07d9964be0fd362772223be6a5f5b6aa",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/commit/be81eb653d633833f2ab22510794abb6bb9c0843",
"tags": [
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/pull/13931",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/pull/13932",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4511---2023-11-16",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/craftcms/cms/blob/v3/CHANGELOG.md#396---2023-11-16",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/craftcms/cms/commit/76caf9af07d9964be0fd362772223be6a5f5b6aa",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/craftcms/cms/commit/be81eb653d633833f2ab22510794abb6bb9c0843",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/craftcms/cms/pull/13931",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/craftcms/cms/pull/13932",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/craftcms/cms/security/advisories/GHSA-j5g9-j7r4-6qvx",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions."
},
{
"lang": "es",
"value": "Craft es un sistema de gestión de contenidos. Esta es una posible vulnerabilidad de escalada de privilegios de baja complejidad y impacto moderado en Craft a partir de 3.x anterior a 3.9.6 y 4.x anterior a 4.4.16 con ciertas configuraciones de permisos de usuario. Esto se ha solucionado en Craft 4.4.16 y Craft 3.9.6. Los usuarios deben asegurarse de estar ejecutando al menos esas versiones."
}
],
"lastModified": "2026-06-17T07:09:51.850",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36AC4498-6DDF-4F74-BD12-86BF5479F10A",
"versionEndExcluding": "3.9.6",
"versionStartIncluding": "3.0.0"
},
{
"criteria": "cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B004CCA-A979-42AD-ADD4-1BEFDB964C78",
"versionEndIncluding": "4.5.15",
"versionStartIncluding": "4.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}