Skip to main content

CVE-2024-24790

CVE Details

CVE-2024-24790

Last Update

08/06/2024

NIST CVE Summary

The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.

Our Official Summary

Waiting on the 3rd party vendor for a fix. Notes: This vulnerability is reported on the mongodb container. A ticket is filed with the vendor to get a new image that addresses the vulnerabilities reported.

CVE Severity

9.8

Status

Ongoing

Affected Products & Versions

  • Palette Enterprise 4.4.14, 4.4.18

Revision History

  • 1.0 08/06/2024 Initial Publication
  • 2.0 09/17/2024 Added Palette Enterprise 4.4.18 to Affected Products