CVE-2024-36885
Description
This CVE is under investigation by Red Hat Product Security.
Statement
This CVE has been marked as Rejected by the assigning CNA.
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability,Access Control,Other
Technical Impact: Bypass Protection Mechanism; Read Application Data; Gain Privileges or Assume Identity; Varies by Context
Active debug code can create unintended entry points or expose sensitive information. The severity of the exposed debug code will depend on the particular instance. At the least, it will give an attacker sensitive information about the settings and mechanics of web applications on the server. At worst, as is often the case, the debug code will allow an attacker complete control over the web application and server, as well as confidential information that either of these access.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.