Main
Vulnerability Database
Exploits
ID:10998 - Exploit for Improper authorization in crypto - CVE-2024-45337
ID:10998 - Exploit for Improper authorization in crypto - CVE-2024-45337
Published: December 19, 2024
Vulnerability identifier: #VU101777
Vulnerability risk: Medium
CVE-ID: CVE-2024-45337
CWE-ID: CWE-285
Exploitation vector: Remote access
Vulnerable software:
crypto
crypto
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to the application.
The vulnerability exists due to improper authorization caused by improper usage of the ServerConfig.PublicKeyCallback callback. A remote attacker can bypass authorization in certain cases and gain access to the application.
Remediation
Install updates from vendor's website.