CVE-2024-41628
Cluster Control CMON API - Directory Traversal
Record summary
CVE-2024-41628 has a selected CVSS score of 7.5 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
clustercontrolBrowse severalnines / clustercontrolDefault status: unknown | CVE List | 1.9.8 to < 1.9.8-9778 | affected |
| 2.0.0 to < 2.0.0-9779 | affected | ||
| 2.1.0 to < 2.1.0-9780 | affected |
Proofs of concept
1Repository PoCs
GitHubRedshift-CyberSecurity/CVE-2024-41628Repository PoCby Redshift-CyberSecurityStars: 2Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHCluster Control CMON API - Directory TraversalCVSS 7.5
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.
Impact
Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Cluster Control server.
Remediation
Update Severalnines Cluster Control to version 1.9.8-9778, 2.0.0-9779, or 2.1.0-9780 or later.
Source: ProjectDiscovery