CVE-2024-9802

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-9802
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-9802.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-9802
Published
2024-10-10T08:15:04.387Z
Modified
2025-11-20T12:32:02.572025Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The conformance validation endpoint is public so everybody can verify the conformance of onboarded services. The response could contain specific information about the service, including available endpoints, and swagger. It could advise about the running version of a service to an attacker. The attacker could also check if a service is running.

References

Affected packages

Git / github.com/zowe/api-layer

Affected ranges

Type
GIT
Repo
https://github.com/zowe/api-layer
Events

Affected versions

Zowe_2.*

Zowe_2.12.0
Zowe_2.13.0
Zowe_2.14.0
Zowe_2.15.0
Zowe_2.16.0

v2.*

v2.11.0
v2.11.1
v2.11.2
v2.11.3
v2.11.4
v2.11.5
v2.12.0
v2.12.1
v2.12.2
v2.12.3
v2.12.4
v2.12.5
v2.12.6
v2.12.7
v2.12.8
v2.12.9
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.13.4
v2.13.5
v2.13.6
v2.13.7
v2.14.0
v2.14.1
v2.14.2
v2.14.3
v2.14.4
v2.14.5
v2.14.6
v2.14.7
v2.14.8
v2.15.0
v2.15.1
v2.16.0
v2.16.1
v2.16.2
v2.16.3