CVE-2024-31851
CData Sync < 23.4.8843 - Path Traversal
Record summary
CVE-2024-31851 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 5, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected, unknown | CVE List | Before 23.4.8843 | affected |
Nuclei templates
1ProjectDiscoveryHIGHCData Sync < 23.4.8843 - Path TraversalCVSS 8.6
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
Impact
Unauthenticated attackers can access sensitive information and perform limited unauthorized actions via path traversal.
Remediation
Update CData Sync to version 23.4.8843 or later.
Source: ProjectDiscovery