PT-2024-35169 · Sftpgo · Sftpgo

Hyperreality

·

Published

2024-11-21

·

Updated

2024-11-23

·

CVE-2024-52309

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions SFTPGo versions prior to 2.6.3
Description SFTPGo has a feature that allows the EventManager to execute scripts or run applications in response to certain events. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. The issue allows potential remote code execution.
Recommendations For versions prior to 2.6.3, consider upgrading to version 2.6.3 or later, where running system commands is disabled by default and an allow list has been added to define which commands are allowed to be configured from the WebAdmin UI. As a temporary workaround, restrict the EventManager to be used only by SFTPGo administrators who also have shell access.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-52309
GHSA-49CC-XRJF-9QF7
GO-2024-3283
OPENSUSE-SU-2024:14519-1

Affected Products

Sftpgo