RULE(RULE ID:338786)

Rule General Information
Release Date: 2025-04-08
Rule Name: Ganglia Web Interface Cross Site Scripting Vulnerability (CVE-2024-52762)
Severity:
CVE ID:
Rule Protection Details
Description: Ganglia is a distributed system monitoring tool that enables real-time monitoring and data analysis of servers. It uses the topology diagram of the tree structure to describe the relationship between the system and the network, and supports a variety of different metrics. A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "tz" parameter.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://github.com/ganglia/ganglia-web/issues/382
Solutions
Please contact the software vendor to update the software patch.