PT-2024-37183 · Stitionai · Devika+1
Published
2024-07-03
·
Updated
2024-07-12
·
CVE-2024-5821
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
No specific software or versions are mentioned.
Description:
The issue allows an attacker to access sensitive files on the server by providing incorrect file names, which the agent attempts to correct, inadvertently revealing the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Devika
Stitionai/Devika