PT-2024-20252 · Unknown · Devan-Kerman Arrp

Apple502J

·

Published

2024-03-18

·

Updated

2024-08-27

·

CVE-2024-24042

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devan-Kerman ARRP versions 0.8.1 and before
Description The issue allows a remote attacker to execute arbitrary code via the dumpDirect in RuntimeResourcePackImpl component. This enables the attacker to potentially access and manipulate files on the system, leading to unauthorized actions.
Recommendations For Devan-Kerman ARRP versions 0.8.1 and before, consider disabling the dumpDirect function in the RuntimeResourcePackImpl component as a temporary workaround until a patch is available. Restrict access to the RuntimeResourcePackImpl component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-24042
GHSA-CG24-JJR5-RXMF

Affected Products

Devan-Kerman Arrp