Network Service auth bypass (CVE-2024-0002)
CVE-2024-0002
Attackers bypass authentication to access protected resources in Network Service and API Gateway. Update to the latest patched version immediately.
Vendor-confirmed - CVE-2024-0002 is a high severity authentication bypass in Network Service 3.x through 3.5.2 that lets attackers gain unauthorized access to sensitive data and escalate privileges. Upgrade to version 3.5.3 immediately to block exploitation.
Overview
A high-severity authentication bypass vulnerability has been discovered in Network Service. This flaw allows attackers to circumvent authentication mechanisms and gain unauthorized access to protected resources.
Impact
Exploitation of this vulnerability could result in:
- Unauthorized access to sensitive data and configurations
- Ability to perform actions as authenticated users
- Potential for privilege escalation within the application
Who Is Affected
This vulnerability affects:
- Network Service versions 3.x through 3.5.2
- API Gateway configurations using Network Service for authentication
Remediation
Immediate Actions:
- Upgrade Network Service to version 3.5.3 or later
- Review access logs for signs of unauthorized access
- Implement additional authentication layers (MFA) where possible
Workaround: If immediate patching is not feasible, restrict access to the authentication endpoints using firewall rules or network segmentation.
Long-term Recommendations:
- Conduct a security audit of authentication mechanisms
- Implement robust logging and alerting for authentication events
- Consider adopting zero-trust architecture principles
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
ApostropheCMS is an open-source content management framework. Prior to version 4.28.0, the bearer token authentication middleware in `@apostrophecms/express/index.js` (lines 386-389) contains an incor...
authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Assertion Signature under Verification Certificate enabl...
Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. Th...
Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on a...