This issue affects PlexTrac: from 1.61.3 before 2.8.1.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51050 | Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue affects PlexTrac: from 1.61.3 before 2.8.1. |
Fri, 10 Oct 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:plextrac:plextrac:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 17 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Dec 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes. This issue affects PlexTrac: from 1.61.3 before 2.8.1. | |
| Title | Insecure YAML Deserialization | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: PlexTrac
Published:
Updated: 2024-12-17T14:31:34.017Z
Reserved: 2024-12-16T19:05:12.284Z
Link: CVE-2024-12687
Updated: 2024-12-17T14:31:30.380Z
Status : Analyzed
Published: 2024-12-16T20:15:09.777
Modified: 2025-10-10T18:30:49.573
Link: CVE-2024-12687
No data.
OpenCVE Enrichment
Updated: 2025-07-12T16:01:37Z
EUVD