CVE-2024-6398

MEDIUM

SWG <12.2.10-11.2.24 - Info Disclosure

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a customizable block page to be disclosed to third-party websites due to Same Origin Policy Bypass of browsers in certain scenarios. The risk is low, because other recommended default security policies such as URL categorization and GTI are in place in most policies to block access to uncategorized/high risk websites. Any information disclosed depends on how the customers have customized the block pages.

References (1)

Core 1
Core References

Scores

CVSS v3 4.3
EPSS 0.0033
EPSS Percentile 24.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
skyhighsecurity/secure_web_gateway 11.0.0 - 11.2.24
Published Jul 15, 2024
Tracked Since Feb 18, 2026