PT-2024-22895 · Alldata · Alldata
Raybye
·
Published
2024-04-01
·
Updated
2025-05-07
·
CVE-2024-29435
CVSS v3.1
4.1
Medium
| Vector | AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Alldata version 0.4.6
Description
An issue in Alldata allows an attacker to run arbitrary commands via the
processId parameter.Recommendations
For Alldata version 0.4.6, avoid using the
processId parameter until a fix is available. As a temporary workaround, consider restricting access to the affected functionality to minimize the risk of exploitation.Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alldata