CVE-2024-38449

A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.
Configurations

No configuration.

History

21 Nov 2024, 09:25

Type Values Removed Values Added
References () https://github.com/kasmtech/KasmVNC/issues/254 - () https://github.com/kasmtech/KasmVNC/issues/254 -
References () https://kasmweb.atlassian.net/servicedesk/customer/portal/3/topic/30ffee7f-4b85-4783-b118-6ae4fd8b0c52 - () https://kasmweb.atlassian.net/servicedesk/customer/portal/3/topic/30ffee7f-4b85-4783-b118-6ae4fd8b0c52 -
References () https://kasmweb.com/kasmvnc - () https://kasmweb.com/kasmvnc -

06 Nov 2024, 17:35

Type Values Removed Values Added
CWE CWE-22
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.7

20 Jun 2024, 12:44

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de Directory Traversal en KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 y posiblemente versiones anteriores permite a atacantes remotos autenticados explorar directorios principales y leer el contenido de archivos fuera del alcance de la aplicación.

17 Jun 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-17 19:15

Updated : 2024-11-21 09:25


NVD link : CVE-2024-38449

Mitre link : CVE-2024-38449

CVE.ORG link : CVE-2024-38449


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')