CVE-2024-12108: critical vulnerability in Progress Software Corporation WhatsUp Gold
WhatsUp Gold - Public API signing key rotation issue
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
WhatsUp Gold versions before 2024.0.2 have a flaw in how they manage signing keys for their public API, allowing attackers to gain unauthorized access to the server. This is critical because it bypasses authentication protections.
The vulnerability stems from improper handling of API signing key rotation in WhatsUp Gold prior to version 2024.0.2. An attacker can exploit this to forge or bypass API authentication mechanisms, gaining unauthorized access to the server. The attack vector is network-based through the public API interface without requiring prior credentials.
In the same product, most dangerous first.