Record summary

CVE-2024-31849 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 4, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE ListBefore 23.4.8846affected

Nuclei templates

1
ProjectDiscoveryCRITICALCData Connect < 23.4.8846 - Path TraversalCVSS 9.8

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

Impact

Unauthenticated attackers can exploit path traversal to gain complete administrative access to CData Connect.

Remediation

Update CData Connect to version 23.4.8846 or later.

WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagscvecve2024cdatalfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Shodan: title:"CData Connect"

Source: ProjectDiscovery

References

2