CVE-2024-38485

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
09/12/2024
Last modified:
04/02/2025

Description

Dell ECS, versions prior to 3.8.0, contain(s) a Host Header Injection Vulnerability. A remote low-privileged attacker could potentially exploit this vulnerability to trigger redirections that leads to sensitive information leakage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:elastic_cloud_storage:*:*:*:*:*:*:*:* 3.8.0.0 (excluding)