CVE-2024-38537 is a critical vulnerability affecting the ethyca fides privacy engineering platform, specifically its fides.js client-side script. It allowed malicious script execution from the compromised polyfill.io domain for users of legacy browsers (e.g., IE11) that did not support the fetch standard. With a CVSS score of 9.8 (CRITICAL), the vulnerability had high impacts on confidentiality, integrity, and availability, though it required user interaction with a vulnerable browser. While no active exploitation has been identified, the vulnerability was patched in Fides version 2.39.1, and a domain-level intervention on June 27, 2024, rendered it unexploitable.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.39.1CPE matchmatch criteria | cpe:2.3:a:ethyca:fides:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.