PT-2024-28009 · Kasmvnc · Kasmvnc
D0Td0Tslash
·
Published
2024-06-17
·
Updated
2024-11-06
·
CVE-2024-38449
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
KasmVNC versions 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and earlier
Description
A Directory Traversal issue allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.
Recommendations
For KasmVNC version 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and earlier, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kasmvnc