Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to release_21.05) were amended with the below patch. Users are advised to upgrade. There are no known workarounds for this vulnerability.
History

Fri, 20 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
Description Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to release_21.05) were amended with the below patch. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Title Possible Data Tampering & Loss of Public Datasets in Galaxy
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-09-20T18:56:53.987Z

Updated: 2024-09-20T20:08:03.491Z

Reserved: 2024-07-30T14:01:33.922Z

Link: CVE-2024-42351

cve-icon Vulnrichment

Updated: 2024-09-20T20:07:53.465Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-20T19:15:15.857

Modified: 2024-09-26T13:32:55.343

Link: CVE-2024-42351

cve-icon Redhat

No data.