PT-2024-22959 · Unknown · Zly2006 Reden

Apple502J

·

Published

2024-04-04

·

Updated

2024-08-16

·

CVE-2024-29672

CVSS v3.1

8.8

High

VectorAC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:R
Name of the Vulnerable Software and Affected Versions zly2006 Reden versions prior to 0.2.514
Description A Directory Traversal issue allows a remote attacker to execute arbitrary code via the DEBUG RTC REQUEST SYNC DATA in KeyCallbacks.kt. This enables the attacker to potentially access and manipulate sensitive data.
Recommendations For versions prior to 0.2.514, update to version 0.2.514 or later to resolve the issue. As a temporary workaround, consider restricting access to the DEBUG RTC REQUEST SYNC DATA in KeyCallbacks.kt to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-29672

Affected Products

Zly2006 Reden