Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-22024", "assignerOrgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1", "state": "PUBLISHED", "assignerShortName": "hackerone", "dateReserved": "2024-01-04T01:04:06.574Z", "datePublished": "2024-02-13T04:07:04.355Z", "dateUpdated": "2024-08-01T22:35:34.846Z"}, "containers": {"cna": {"descriptions": [{"lang": "en", "value": "An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication."}], "affected": [{"vendor": "Ivanti", "product": "ICS", "versions": [{"version": "9.1R14.5", "status": "affected", "lessThan": "9.1R14.5", "versionType": "semver"}, {"version": "9.1R17.3", "status": "affected", "lessThan": "9.1R17.3", "versionType": "semver"}, {"version": "9.1R18.4", "status": "affected", "lessThan": "9.1R18.4", "versionType": "semver"}, {"version": "22.1R6.1", "status": "affected", "lessThan": "22.1R6.1", "versionType": "semver"}, {"version": "9.1R14.4", "status": "unaffected", "lessThan": "9.1R14.4", "versionType": "semver"}, {"version": "9.1R15.2", "status": "unaffected", "lessThan": "9.1R15.2", "versionType": "semver"}, {"version": "9.1R16.2", "status": "unaffected", "lessThan": "9.1R16.2", "versionType": "semver"}, {"version": "9.1R17.2", "status": "unaffected", "lessThan": "9.1R17.2", "versionType": "semver"}, {"version": "9.1R18.3", "status": "unaffected", "lessThan": "9.1R18.3", "versionType": "semver"}, {"version": "22.1R6.1", "status": "unaffected", "lessThan": "22.1R6.1", "versionType": "semver"}, {"version": "22.2R4.1", "status": "affected", "lessThan": "22.2R4.1", "versionType": "semver"}, {"version": "22.3R1.1", "status": "affected", "lessThan": "22.3R1.1", "versionType": "semver"}, {"version": "22.4R1.1", "status": "affected", "lessThan": "22.4R1.1", "versionType": "semver"}, {"version": "22.5R1.2", "status": "affected", "lessThan": "22.5R1.2", "versionType": "semver"}, {"version": "22.6R1.1", "status": "affected", "lessThan": "22.6R1.1", "versionType": "semver"}, {"version": "22.4R2.3", "status": "affected", "lessThan": "22.4R2.3", "versionType": "semver"}, {"version": "22.5R2.3", "status": "affected", "lessThan": "22.5R2.3", "versionType": "semver"}, {"version": "22.6R2.2", "status": "affected", "lessThan": "22.6R2.2", "versionType": "semver"}, {"version": "22.2R4.1", "status": "unaffected", "lessThan": "22.2R4.1", "versionType": "semver"}, {"version": "22.3R1", "status": "unaffected", "lessThan": "22.3R1", "versionType": "semver"}, {"version": "22.4R1.1", "status": "unaffected", "lessThan": "22.4R1.1", "versionType": "semver"}, {"version": "22.5R1.1", "status": "unaffected", "lessThan": "22.5R1.1", "versionType": "semver"}, {"version": "22.6R1.1", "status": "unaffected", "lessThan": "22.6R1.1", "versionType": "semver"}, {"version": "22.4R2.2", "status": "unaffected", "lessThan": "22.4R2.2", "versionType": "semver"}, {"version": "22.5R2.2", "status": "unaffected", "lessThan": "22.5R2.2", "versionType": "semver"}, {"version": "22.6R2.2", "status": "unaffected", "lessThan": "22.6R2.2", "versionType": "semver"}]}, {"vendor": "Ivant ", "product": "ICS", "versions": [{"version": "9.1R15.3", "status": "affected", "lessThan": "9.1R15.3", "versionType": "semver"}]}, {"vendor": "Ivanti", "product": "IPS", "versions": [{"version": "9.1R18.4", "status": "affected", "lessThan": "9.1R18.4", "versionType": "semver"}, {"version": "9.1R17.3", "status": "affected", "lessThan": "9.1R17.3", "versionType": "semver"}, {"version": "22.5R1.2", "status": "affected", "lessThan": "22.5R1.2", "versionType": "semver"}, {"version": "9.1R18.2", "status": "unaffected", "lessThan": "9.1R18.2", "versionType": "semver"}, {"version": "9.1R17.2", "status": "unaffected", "lessThan": "9.1R17.2", "versionType": "semver"}, {"version": "22.5R1.1", "status": "unaffected", "lessThan": "22.5R1.1", "versionType": "semver"}]}], "references": [{"url": "https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US"}], "metrics": [{"cvssV3_0": {"version": "3.0", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L", "baseScore": 8.3, "baseSeverity": "HIGH"}}], "providerMetadata": {"orgId": "36234546-b8fa-4601-9d6f-f4e334aa8ea1", "shortName": "hackerone", "dateUpdated": "2024-02-13T04:07:04.355Z"}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-01T22:35:34.846Z"}, "title": "CVE Program Container", "references": [{"url": "https://forums.ivanti.com/s/article/CVE-2024-22024-XXE-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure?language=en_US", "tags": ["x_transferred"]}]}]}}