Security Updates - Fix for CVE-2024-1212
- Last Updated: February 6, 2025
- 1 minute read
- LoadMaster
- LoadMaster GA
- Documentation
Refer to the following section for security updates relating to this release.
Fix for CVE-2024-1212
In previous releases of LoadMaster, a user who has access to the management network on which the LoadMaster administrative IP address resides can, using a carefully crafted RESTful API command, log into LoadMaster without credentials and execute privileged API commands. This update contains a fix for this issue and closes this vulnerability. For more information, please see the related Support Knowledge Base article.