Skip to main content
Version: latest

CVE-2024-37370

CVE Details

CVE-2024-37370

Last Update

8/30/2024

NIST CVE Summary

In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.

Our Official Summary

This CVE is a message token handling issue reported on kerboros libraries. This affects krb5 packages in versions less than 1.21.3-1. Exploitation of this flaw could cause system crashes. Risk of this specific vulnerability for spectro cloud components is low. Working on removing/upgrading libraries to fix the issue.

CVE Severity

7.5

Status

Ongoing

Affected Products & Versions

  • Palette VerteX 4.4.14, 4.4.18
  • Palette Enterprise 4.4.18

Revision History

  • 1.0 08/16/2024 Initial Publication
  • 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products
  • 3.0 09/17/2024 Added Palette VerteX 4.4.18 & Palette Enterprise 4.4.18 to Affected Products