Vulnerabilities > CVE-2024-45597 - Unspecified vulnerability in Pluto-Lang Pluto
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
LOW Availability impact
NONE Summary
Pluto is a superset of Lua 5.4 with a focus on general-purpose programming. Scripts passing user-controlled values to http.request header values are affected. An attacker could use this to send arbitrary requests, potentially leveraging authentication tokens provided in the same headers table.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |