Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.
Fixes

Solution

Upgrade Arctic Hub to version 5.6.1877 or above.


Workaround

If upgrading is not possible, apply the hotfix as instructed in the version 5.6.1877 release note which was distributed to all Arctic Hub users on 12th of December 2024.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00126}

epss

{'score': 0.00135}


Tue, 24 Dec 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
Description Server-Side Request Forgery in URL Mapper in Arctic Security's Arctic Hub versions 3.0.1764-5.6.1877 allows an unauthenticated remote attacker to exfiltrate and modify configurations and data.
Title Server-Side Request Forgery in Arctic Hub URL Mapper allows an unauthenticated remote attacker to exfiltrate and modify configurations and data
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:L/SA:N/AU:N/R:U/V:C/RE:M/U:Amber'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC-FI

Published:

Updated: 2024-12-24T16:59:02.357Z

Reserved: 2024-12-20T19:11:54.846Z

Link: CVE-2024-12867

cve-icon Vulnrichment

Updated: 2024-12-24T16:58:56.885Z

cve-icon NVD

Status : Received

Published: 2024-12-20T20:15:22.740

Modified: 2024-12-20T20:15:22.740

Link: CVE-2024-12867

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.