Logging Bypass in Progress MOVEit Transfer < 2022.0.11 / 2023.1.4
CVE-2024-2291 Published on March 20, 2024
MOVEit Transfer Logging Bypass Vulnerability
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered. An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
Vulnerability Analysis
CVE-2024-2291 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
Insufficient Logging
When a security-critical event occurs, the software either does not record the event or omits important details about the event when logging it. When security-critical events are not logged properly, such as a failed login attempt, this can make malicious behavior more difficult to detect and may hinder forensic analysis after an attack succeeds.
Products Associated with CVE-2024-2291
Want to know whenever a new CVE is published for Progress Moveit Transfer? stack.watch will email you.
Affected Versions
Progress Software MOVEit Transfer:- Version 2022.0.0 (14.0.0) and below 2022.0.11 (14.0.11) is affected.
- Version 2022.1.0 (14.1.0) and below 2022.1.12 (14.1.12) is affected.
- Version 2023.0.0 (15.0.0) and below 2023.0.9 (15.0.9) is affected.
- Version 2023.1.0 (15.1.0) and below 2023.1.4 (15.1.4) is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.