Unvalidated Redirect Vulnerability in ArcGIS Could Simplify Phishing Attacks
CVE-2024-8148

6.1MEDIUM

Key Information:

Vendor

Esri

Vendor
CVE Published:
4 October 2024

What is CVE-2024-8148?

An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS versions 10.8.1 to 11.2, which may enable a remote attacker, without authentication, to craft a malicious URL that redirects users to arbitrary websites. This flaw can facilitate phishing attacks, potentially compromising sensitive user data. Organizations using affected versions should consider applying security updates to mitigate this risk and enhance their overall cybersecurity posture.

Affected Version(s)

Portal for ArcGIS all <= 11.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.