PT-2024-2870 · Eclipse+1 · Jetty+1
Evan Grant
·
Published
2024-03-04
·
Updated
2024-05-10
·
CVE-2024-31851
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CData Sync versions prior to 23.4.8843
Description
A path traversal vulnerability exists in the Java version of CData Sync when running using the embedded Jetty server. This issue is related to errors in handling relative paths to directories. Exploitation of this vulnerability could allow a remote attacker to gain unauthorized access to protected information and perform limited actions in the system by sending specially crafted HTTP requests.
Recommendations
For versions prior to 23.4.8843, update to version 23.4.8843 or later to resolve the issue. As a temporary workaround, consider restricting access to the embedded Jetty server to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cdata Sync
Jetty