CVE-2024-34014

Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.
Configurations

No configuration.

History

12 Nov 2024, 13:55

Type Values Removed Values Added
Summary
  • (es) Sobrescritura arbitraria de archivos durante la recuperación debido a un manejo incorrecto de enlaces simbólicos. Los siguientes productos se ven afectados: Acronis Backup plugin for cPanel & WHM (Linux) anterior a la compilación 818, Acronis Backup extension for Plesk (Linux) anterior a la compilación 599, Acronis Backup plugin for DirectAdmin (Linux) anterior a la compilación 181.

11 Nov 2024, 22:15

Type Values Removed Values Added
Summary (en) Arbitrary file overwrite during recovery due to improper soft link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181. (en) Arbitrary file overwrite during recovery due to improper symbolic link handling. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 818, Acronis Backup extension for Plesk (Linux) before build 599, Acronis Backup plugin for DirectAdmin (Linux) before build 181.

11 Nov 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-11 14:15

Updated : 2024-11-12 13:55


NVD link : CVE-2024-34014

Mitre link : CVE-2024-34014

CVE.ORG link : CVE-2024-34014


JSON object : View

Products Affected

No product.

CWE
CWE-61

UNIX Symbolic Link (Symlink) Following