PT-2024-30555 · Unknown · Craftos-Pc 2

Graypinkfurball

·

Published

2024-08-16

·

Updated

2024-08-19

·

CVE-2024-43395

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions CraftOS-PC 2 versions prior to 2.8.3
Description The issue allows users of CraftOS-PC 2 on Windows to escape the computer folder and access files anywhere without permission or notice by obfuscating ..s to bypass the internal check preventing parent directory traversal. This is achieved by exploiting a weakness in the internal checks, allowing unauthorized access to files.
Recommendations For versions prior to 2.8.3, update to version 2.8.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-43395
GHSA-HR3W-WC83-6923

Affected Products

Craftos-Pc 2