CVE-2024-43177
published 2024-10-22CVE-2024-43177: IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
PriorityP343critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.32%
23.6th percentile
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | concert | — | — |
| ibm | concert | — | — |
| ibm | concert | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jrw2-3gwx-j89g: IBM Concert 1
ghsa_unreviewed·2024-10-22
CVE-2024-43177 [MEDIUM] CWE-295 GHSA-jrw2-3gwx-j89g: IBM Concert 1
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the SameSite attribute.
OSV
ruby-devise-two-factor vulnerabilities
osv·2024-10-01·CVSS 5.3
CVE-2021-43177 ruby-devise-two-factor vulnerabilities
ruby-devise-two-factor vulnerabilities
Benoit Côté-Jodoin and Michael Nipper discovered that Devise-Two-Factor
incorrectly handled one-time password validation. An attacker could
possibly use this issue to intercept and re-use a one-time password.
(CVE-2021-43177)
Garrett Rappaport discovered that Devise-Two-Factor incorrectly handled
generating multi-factor authentication codes. An attacker could possibly
use this issue to generate valid multi-factor authentication codes.
(CVE-2024-8796)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-10-22
Published