CVE-2024-30170

critical

Description

PrivX before 34.0 allows data exfiltration and denial of service via the REST API. This is fixed in minor versions 33.1, 32.3, 31.3, and later, and in major version 34.0 and later,

References

https://privx.docs.ssh.com/docs/security

https://info.ssh.com/improper-input-validation-faq

Details

Source: Mitre, NVD

Published: 2024-08-06

Updated: 2024-08-12

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:C

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Severity: Critical

EPSS

EPSS: 0.0038