CVE-2024-41801

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jul 25, 2024
Updated: Jul 26, 2024
CWE ID 601

Summary

CVE-2024-41801: OpenProject, an open-source project management software, has a vulnerability affecting versions prior to 14.3.0. An attacker could manipulate HOST headers and initiate phishing attacks by redirecting users to remote hosts. This issue impacts default installations running on Apache without additional security measures like mod_security or manually set host names. Version 14.3.0 introduces stronger protections through the HostAuthorization middleware, ensuring hosted links use the built-in hostname. users unable to upgrade immediately should either apply mod_security or manually fix headers in their proxying applications. A patch is also available for older OpenProject versions to opt-in to host header protections.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Openproject
  • OPF OpenProject

Affected Vendors

  • Openproject

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-41801 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions