CVE-2024-12908

MEDIUM
Published Dec 26, 2024 Modified Oct 15, 2025 CWE-94

Description

Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compared before normalization and canonicalization, potentially leading to over matching against the approved list. If this attack were successfully exploited, a remote attacker may be able to convince a user to visit a malicious web-page, or open a malicious document which could trigger the vulnerable handler, allowing them to execute arbitrary code on the user's machine. Delinea added additional validation that the downloaded installer's batch file was in the expected format.

Is your site exposed to CVE-2024-12908?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

6.9
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N

Weakness Type (CWE)

CWE-94 CWE-94

Affected Products

Vendor Product
delinea secret_server

References

Frequently Asked Questions

What is CVE-2024-12908? +
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26) where, within the protocol handler function, URI's were compared before normalization and canonicalization, potentially leading to over matching against the approved list. If this attack were successfully exploited, a remote attacker may be able to convince a user to visit a malicious web-page, or open a malicious document which could trigger the vulnerable handler, allowing them to execute arbitrary code on the user's machine. Delinea added additional validation that the downloaded installer's batch file was in the expected format. It has a CVSS v3.1 base score of 6.9 (MEDIUM).
How severe is CVE-2024-12908? +
CVE-2024-12908 has a CVSS v3.1 score of 6.9 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2024-12908? +
CVE-2024-12908 affects products from delinea, specifically: secret_server. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-12908? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-12908 — free, no signup required.