CVE-2024-37403

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:*

History

12 Aug 2024, 18:55

Type Values Removed Values Added
References () https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android - () https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android - Vendor Advisory
CVSS v2 : unknown
v3 : 5.0
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:ivanti:docs\@work:*:*:*:*:*:android:*:*
CWE CWE-22
First Time Ivanti
Ivanti docs\@work

07 Aug 2024, 15:17

Type Values Removed Values Added
Summary
  • (es) Ivanti Docs@Work para Android, versiones anteriores a 2.26.0, se ve afectada por la vulnerabilidad 'Dirty Stream'. La aplicación no puede desinfectar adecuadamente los nombres de los archivos, lo que genera una vulnerabilidad relacionada con el path traversal. Esto potencialmente permite que otras aplicaciones maliciosas en el dispositivo lean información confidencial almacenada en la raíz de la aplicación.

07 Aug 2024, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-07 04:17

Updated : 2024-08-12 18:55


NVD link : CVE-2024-37403

Mitre link : CVE-2024-37403

CVE.ORG link : CVE-2024-37403


JSON object : View

Products Affected

ivanti

  • docs\@work
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')