CVE-2024-36858
Jan path traversal vulnerability
Record summary
CVE-2024-36858 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 14, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List, VulnCheck | 0.4.12 | affected |
@janhq/coreBrowse npm / @janhq/core | GitHub Advisory | Through 0.1.11 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALJan v0.4.12 - Arbitrary File UploadCVSS 9.8
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
Impact
Unauthenticated attackers can upload crafted files to execute arbitrary code on the server.
Remediation
Update Jan to a version later than v0.4.12 that patches the arbitrary file upload vulnerability.
Source: ProjectDiscovery