PT-2024-22657 · Dell · Dell Repository Manager

Jakub Brzozowski

+1

·

Published

2024-04-24

·

Updated

2025-01-21

·

CVE-2024-28976

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Repository Manager versions prior to 3.4.5
Description The issue concerns a Path Traversal vulnerability in the API module. A local attacker with low privileges could potentially exploit this to gain unauthorized write access to files on the server filesystem with the privileges of the running web application.
Recommendations For versions prior to 3.4.5, update to version 3.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the API module to minimize the risk of exploitation.

Fix

Path traversal

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-28976

Affected Products

Dell Repository Manager