Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-33434. Notes: All CVE users should reference CVE-2024-33434 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2024-30850 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2024-33434. Reason: This record is a duplicate of CVE-2024-33434. Notes: All CVE users should reference CVE-2024-33434 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.
CVE-2024-30850
- No CVSS published and no exploitation signals yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- —
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- —
- EPSS %ILE
- —
- KEV
- Not listed
Published
April 12, 2024
Last Modified
April 3, 2026
Affected Packages
(1 across 1 ecosystem)
Go(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| github.com/tiagorlampert/CHAOS | — | 0.0.0-20220716132853-b47438d36e3a | — |
Data Freshness Timeline
(refreshed 0× in last 7d / 0× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-23 02:36 UTCEG score recompute
- 2026-05-22 03:15 UTCEG score recompute
- 2026-05-20 08:33 UTCOSV refresh
Publicly available exploits
(2 references)Working exploit code is in the public domain (1 Metasploit module) (1 GitHub PoC). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- Metasploitexploit/linux/http/chaos_rat_xss_to_rce✓ verifiedFirst seen Apr 10, 2024
Chaos RAT XSS to RCE
Open source ↗ - GitHub PoCchebuya/CVE-2024-30850-chaos-rat-rce-pocFirst seen Apr 5, 2024
CHAOS RAT web panel path RCE PoC
Open source ↗
Related CVEs(same product)
Same product
2 shownGo:github.com/tiagorlampert/CHAOS
Frequently asked(3)
What is CVE-2024-30850?
When was CVE-2024-30850 disclosed?
How do I remediate CVE-2024-30850?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-30850
Is Your Infrastructure Affected by CVE-2024-30850?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.