Loading HuntDB...

GHSA-xvx4-v362-295f

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."

Related CVEs

Key Information

GHSA ID
GHSA-xvx4-v362-295f
Published
November 14, 2024 12:31 PM
Last Modified
November 14, 2024 12:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 27, 2025 6:35 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.