CVE-2024-31849
CData Connect < 23.4.8846 - Path Traversal
Record summary
CVE-2024-31849 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ConnectBrowse CData / ConnectDefault status: unaffected, unknown | CVE List | Before 23.4.8846 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALCData Connect < 23.4.8846 - Path TraversalCVSS 9.8
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
Impact
Unauthenticated attackers can exploit path traversal to gain complete administrative access to CData Connect.
Remediation
Update CData Connect to version 23.4.8846 or later.
Source: ProjectDiscovery