CVE-2024-34644
published 2024-09-04CVE-2024-34644: Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User…
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.15%
4.5th percentile
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| samsung | android | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak on Quarkus CLI option for encrypted JGroups ignored
ghsa·2025-02-05
CVE-2024-10973 [MEDIUM] CWE-319 Keycloak on Quarkus CLI option for encrypted JGroups ignored
Keycloak on Quarkus CLI option for encrypted JGroups ignored
The env option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the jgroups replication configuration is always used in plain. This option worked before in 24 and 22. More info in public issue https://github.com/keycloak/keycloak/issues/34644.
GHSA
GHSA-vxrr-25rh-4mqw: Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data
ghsa_unreviewed·2024-09-04
CVE-2024-34644 [MEDIUM] GHSA-vxrr-25rh-4mqw: Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
No detection rules found.
No public exploits indexed.
2024-09-04
Published