Privilege Escalation Vulnerability in GNU Savane
CVE-2024-27632

Currently unrated

Key Information:

Vendor
GNU
Vendor
CVE Published:
8 April 2024

Summary

An identified vulnerability in GNU Savane versions up to 3.12 permits remote attackers to escalate their privileges. This exploit arises from improper handling of the form_id parameter within the form_header() function, allowing unauthorized actions that could compromise the integrity and security of the application. Effective mitigations and timely updates are essential to safeguard against potential exploitation by malicious actors.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.