Host Header Injection Vulnerability in CyberArk Privileged Access Manager Self-Hosted
CVE-2024-54840
6.1MEDIUM
What is CVE-2024-54840?
The Password Vault Web Access (PVWA) component of CyberArk's Privileged Access Manager Self-Hosted exhibits a vulnerability wherein it fails to adequately validate Host headers. This oversight can lead to potential host header injection attacks, allowing malicious users to manipulate the environment in ways that could compromise system integrity. The issue affects versions prior to 14.4, emphasizing the importance of system upgrades for users to mitigate associated risks.
Affected Version(s)
Privileged Access Manager 0 < 14.4