PT-2024-2856 · Eclipse+1 · Jetty+1

Evan Grant

·

Published

2024-03-04

·

Updated

2024-05-10

·

CVE-2024-31848

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CData API Server versions prior to 23.4.8844
Description A path traversal vulnerability exists in the Java version of CData API Server when running using the embedded Jetty server. This could allow an unauthenticated remote attacker to gain complete administrative access to the application. The issue is related to errors in handling relative path to directory due to the lack of session checking for endpoints. Exploitation of the vulnerability may allow a remote attacker to elevate privileges by sending specially crafted HTTP requests. Over 2,500 services are potentially affected.
Recommendations For versions prior to 23.4.8844, update to version 23.4.8844 or later to resolve the issue. As a temporary workaround, consider restricting access to the embedded Jetty server until a patch is applied. Avoid using the vulnerable CData API Server with the embedded Jetty server for sensitive applications until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-03004
CVE-2024-31848

Affected Products

Cdata Api Server
Jetty