CVE-2024-27632 is a high-severity privilege escalation vulnerability affecting GNU Savane versions 3.12 and earlier, allowing a remote attacker to gain elevated privileges by manipulating the form_id in the form_header() function. With a CVSS score of 8.8, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community attention and media coverage, including a mention by a notable cybersecurity researcher.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.13CPE matchmatch criteria | cpe:2.3:a:gnu:savane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.