← back
CVE-2024-42351

Possible Data Tampering & Loss of Public Datasets in Galaxy

CVSS 6.5 MEDIUMEPSS 0.5%CWE-200
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
20 Sep 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to release_21.05) were amended with the below patch. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
galaxyproject · galaxy

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →