Record summary

CVE-2024-31850 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE ListBefore 23.4.8839affected

Nuclei templates

1
ProjectDiscoveryHIGHCData Arc < 23.4.8839 - Path TraversalCVSS 8.6

A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.

Impact

Unauthenticated attackers can access sensitive information and perform limited unauthorized actions via path traversal.

Remediation

Update CData Arc to version 23.4.8839 or later.

WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagscvecve2024cdatalfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CPE: cpe:2.3:a:cdata:arc:*:*:*:*:*:*:*:*
Shodan: title:"CData Arc"

Source: ProjectDiscovery

References

2