PT-2024-10212 · Ixsystems · Truenas Core
Daan Keuper
+2
·
Published
2024-11-27
·
Updated
2025-08-18
·
CVE-2024-11944
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
iXsystems TrueNAS CORE versions prior to 13.0-U6.3
Description
The issue is related to the tarfile.extractall method, which lacks proper validation of a user-supplied path prior to using it in file operations. This allows network-adjacent attackers to execute arbitrary code on affected installations of iXsystems TrueNAS devices without requiring authentication. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root.
Recommendations
For versions prior to 13.0-U6.3, update to version 13.0-U6.3 to resolve the issue.
As a temporary workaround, consider restricting access to the tarfile.extractall method until a patch is available.
Avoid using the
tarfile.extractall method in file operations until the issue is resolved.Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Truenas Core