CVE-2024-31850
CData Arc < 23.4.8839 - Path Traversal
Record summary
CVE-2024-31850 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 8, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected, unknown | CVE List | Before 23.4.8839 | affected |
Nuclei templates
1ProjectDiscoveryHIGHCData Arc < 23.4.8839 - Path TraversalCVSS 8.6
A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
Impact
Unauthenticated attackers can access sensitive information and perform limited unauthorized actions via path traversal.
Remediation
Update CData Arc to version 23.4.8839 or later.
Source: ProjectDiscovery