PT-2024-8753 · Mendix · Mendix Encryption

CVE-2024-39888

·

Published

2024-07-09

·

Updated

2024-07-09

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mendix Encryption versions 10.0.0 through 10.0.1
Description A vulnerability has been identified in the Mendix Encryption module, where affected versions define a specific hard-coded default value for the EncryptionKey constant. This default encryption key can be considered compromised, potentially allowing an attacker to decrypt any encrypted project data. The vulnerability may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For Mendix Encryption versions 10.0.0 through 10.0.1, update to a version outside of this range to secure your projects. As a temporary workaround, consider redefining the EncryptionKey constant with a unique value to minimize the risk of exploitation. Restrict access to encrypted project data until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10357
CVE-2024-39888

Affected Products

Mendix Encryption