The vendor explicitly identifies these products as affected by this CVE.
- Mendix Studio Pro 10.11
- Mendix Studio Pro 10.12
- Mendix Studio Pro 10.13
- Mendix Studio Pro 10.14
- Mendix Studio Pro 10.15
- Mendix Studio Pro 10.16
- Mendix Studio Pro 10.17
- Mendix Studio Pro 10.18
- Mendix Studio Pro 10.19
- Mendix Studio Pro 10.20
- Mendix Studio Pro 10.21
- Mendix Studio Pro 10.22
- Summary
- Affected versions of Mendix Studio Pro do not properly validate or sanitize project files processed during the build pipeline. This could allow an attacker who tricks a user into opening and running a specially crafted malicious project locally on their system to execute arbitrary code in the context of that user.
- Remediation
- Update to V10.24.21 or later version
