PT-2024-30555 · Unknown · Craftos-Pc 2
Graypinkfurball
·
Published
2024-08-16
·
Updated
2024-08-19
·
CVE-2024-43395
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
CraftOS-PC 2 versions prior to 2.8.3
Description
The issue allows users of CraftOS-PC 2 on Windows to escape the computer folder and access files anywhere without permission or notice by obfuscating
..s to bypass the internal check preventing parent directory traversal. This is achieved by exploiting a weakness in the internal checks, allowing unauthorized access to files.Recommendations
For versions prior to 2.8.3, update to version 2.8.3 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craftos-Pc 2