PT-2024-32338 · Genie · Genie

Jmoritzc53

+1

·

Published

2024-05-09

·

Updated

2025-10-25

·

CVE-2024-4701

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Genie versions prior to 4.3.18
Description A path traversal issue exists in Genie that could lead to remote code execution. The issue stems from a vulnerability in the API that accepts file uploads via multipart/form-data. The API uses a user-supplied filename when writing files to disk, allowing a malicious actor to manipulate the filename to perform path traversal. This manipulation could allow writing files with user-specified names and contents to arbitrary locations on the file system where the Java process has write access. Users who do not store file attachments locally are not affected. The issue impacts Genie OSS instances that rely on the filesystem to store file attachments submitted to the application.
Recommendations Upgrade to Genie OSS version 4.3.18.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4701
GHSA-WPCV-5JGP-69F3

Affected Products

Genie