> Source: [sk182743](https://support.checkpoint.com/results/sk/sk182743)

# sk182743 - Check Point Response to CVE-2024-24914 - TCL substitution of global parameter values

| Property | Value |
|----------|-------|
| Solution ID | sk182743 |
| Date Created | 2024-10-08 |
| Last Modified | 2025-02-09 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Scalable Platforms, Multi-Domain Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81.20, R81 (EOS), R81.20, R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |

## Symptoms

- After logging in to Gaia Portal, authenticated users (local Gaia users and RADIUS / TACACS users) may cause code injection in Gaia Portal because of unprotected global variables usage when processing the HTTP request in the TCL process.

This issue received the ID [CVE-2024-24914](https://www.cve.org/CVERecord?id=CVE-2024-24914).

## Solution

This problem was fixed.  
The solution adds a defense mechanism in Gaia Portal against code injections that use special HTTP requests.

The fix is included starting from:

* [Check Point Quantum R82](https://support.checkpoint.com/results/sk/sk181127)
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 79
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 158
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

**Revision History**  
Show / Hide revision history  

|-------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Date        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| 21 Nov 2024 | Added the "Revision History" section                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| 19 Nov 2024 | * In the "Symptoms" section, changed the text from "Authenticated Gaia users may cause code injection because of unprotected global variables usage when processing the HTTP request in TCL process" to "After logging in to Gaia Portal, authenticated users (local Gaia users and RADIUS / TACACS users) may cause code injection in Gaia Portal because of unprotected global variables usage when processing the HTTP request in the TCL process" * In the "Solution" section, changed the text from "The solution adds a defense mechanism against code injections through special HTTP requests" to "The solution adds a defense mechanism in Gaia Portal against code injections through special HTTP requests" |
| 11 Nov 2024 | In the "Solution" section, in the list "The fix is included starting from", added "Check Point Quantum R82"                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| 07 Nov 2024 | First release of this article                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
