Fiche vulnérabilité
CVE-2024-45187 : faille élevée mage mage-ai (CVSS 8.8)
Description
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 23 août 2024
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- mage mage-ai