VYPR
Unrated severityNVD Advisory· Published Nov 4, 2024· Updated Nov 5, 2024

CVE-2024-34883

CVE-2024-34883

Description

Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.

Affected products

2
  • 1C-Bitrix/Bitrix24description
  • Bitrix/Bitrix24llm-fuzzy
    Range: =23.300.100

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.