CVE-2024-2291
MEDIUMDescription
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| progress | moveit_transfer |
| progress | moveit_transfer |
| progress | moveit_transfer |
| progress | moveit_transfer |
References
Frequently Asked Questions
What is CVE-2024-2291? +
How severe is CVE-2024-2291? +
What products are affected by CVE-2024-2291? +
How do I check if I'm vulnerable to CVE-2024-2291? +
Related Vulnerabilities
: Insufficient Logging vulnerability in OpenText Secure Content Manager on Windows allows Audit Log Manipulation.This issue affects Secure Content Manager: …
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent …
Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a …
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions …
Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks.This issue affects Mediawiki - AbuseFilter Extension: …
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, …