The Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-2024.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avalara
Avalara avalara For Salesforce Cpq |
|
| CPEs | cpe:2.3:a:avalara:avalara_for_salesforce_cpq:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Avalara
Avalara avalara For Salesforce Cpq |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-07-03T00:00:00.000Z
Updated: 2024-08-02T04:12:25.111Z
Reserved: 2024-06-16T00:00:00.000Z
Link: CVE-2024-38453
Updated: 2024-08-02T04:12:25.111Z
Status : Awaiting Analysis
Published: 2024-07-03T06:15:04.240
Modified: 2024-11-21T09:25:54.890
Link: CVE-2024-38453
No data.