PT-2019-14004 · Code42 · Code42 Enterprise

Publicado

2019-09-17

·

Atualizado

2019-09-17

·

CVE-2019-15131

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Code42 Enterprise versions 6.7.5 and earlier Code42 Enterprise versions 6.8.4 through 6.8.8 Code42 Enterprise version 7.0.0
Description A vulnerability has been identified that may allow arbitrary files to be uploaded to Code42 servers and executed, potentially leading to code execution. This issue could enable an attacker to create directories and save files on Code42 servers.
Recommendations For Code42 Enterprise versions 6.7.5 and earlier, update to a version later than 6.7.5 to resolve the issue. For Code42 Enterprise versions 6.8.4 through 6.8.8, update to a version later than 6.8.8 to resolve the issue. For Code42 Enterprise version 7.0.0, update to a version later than 7.0.0 to resolve the issue.

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-15131

Produtos afetados

Code42 Enterprise