PT-2024-12248 · Unknown · Forward App+1
Published
2024-01-29
·
Updated
2024-02-07
·
CVE-2023-30970
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gotham Table service (affected versions not specified)
Forward App (affected versions not specified)
Description
The issue allows an authenticated user to read arbitrary files on the file system due to a Path traversal problem.
Recommendations
For Gotham Table service, restrict access to sensitive files on the file system until a fix is available.
For Forward App, consider implementing additional authentication or authorization checks to minimize the risk of exploitation.
As a temporary workaround, consider disabling any features that allow file system access until a patch is available.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Forward App
Gotham Table Service