CVE Feed

    Dashboard / CVE / CVE-2024-42351

    CVE-2024-42351

    Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. An attacker can potentially replace the contents of public datasets resulting in data loss or tampering. All supported branches of Galaxy (and more back to release_21.05) were amended with the below patch. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Published:Sep 20, 2024
    Last Modified:Aug 15, 2025
    EPS:Sep 20, 2024
    EPSS Score:0.00138
    CVSS Score:6.5

    Affected Products

    Vendor
    Galaxyproject
    Product
    Galaxy

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High