PT-2024-21978 · Gnu · Gnu Savane

Ally-Petitt

·

Published

2024-04-08

·

Updated

2025-09-02

·

CVE-2024-27630

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNU Savane versions 3.12 and earlier
Description The issue allows a remote attacker to delete arbitrary files via crafted input to the trackers data delete file function. This is due to an Insecure Direct Object Reference (IDOR) in the software.
Recommendations For GNU Savane versions 3.12 and earlier, as a temporary workaround, consider disabling the trackers data delete file function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-27630

Affected Products

Gnu Savane