ArcGIS Trust Center

Portal for ArcGIS Security 2024 Update 1 released

Esri has released the Portal for ArcGIS Security 2024 Update 1 Patch, resolving multiple high and medium severity security vulnerabilities across versions 11.2, 11.1, 10.9.1 and 10.8.1

 

This patch was released on April 4th, 2024, and is available here.

 

We provide Common Vulnerability Scoring System v.3.1 (CVSS) scores to allow our customers to better assess the risk of these vulnerabilities to their operations. Both base and modified temporal scores are provided to reflect the availability of an official patch.

Vulnerabilities fixed by this patch.

Cross-Site Request Forgery (CSRF)

 

Cross Site Scripting – (XSS)

 

Cross Site Scripting – (XSS)

Acknowledgements: Pedro Pinho

Cross Site Scripting – (XSS)

Acknowledgements: Pedro Pinho

 

Cross Site Scripting – (XSS)

 

Cross Site Scripting – (XSS)

 

Directory Traversal – (Path Traversal)

Acknowledgements: Adam Willard

 

Cross Site Scripting – (XSS)

 

Access Control – (Improper Authentication)

Next Article

Harnessing the Power of Imagery: A Programmatic Approach

Read this article