CVE-2014-3702: Path Traversal
A path traversal flaw was found in eDeploy's session parameter handler. A remote attacker could use this flaw to create arbitrary directories on the server, potentially leading to a denial-of-service.
Other sources
Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3702?
CVE-2014-3702 has a medium severity level due to its potential for creating arbitrary directories, leading to denial-of-service.
How do I fix CVE-2014-3702?
To fix CVE-2014-3702, you should upgrade to a patched version of Red Hat eDeploy that resolves this path traversal vulnerability.
Which versions of Red Hat eDeploy are affected by CVE-2014-3702?
CVE-2014-3702 affects versions 0.1.0, 0.2.0, 1.4.0, 1.5.0, h.1.0.0, h.1.1.0, h.1.2.0, and h.1.3.0 of Red Hat eDeploy.
Can CVE-2014-3702 be exploited remotely?
Yes, CVE-2014-3702 can be exploited remotely by an attacker to create arbitrary directories on the server.
What is a path traversal vulnerability in the context of CVE-2014-3702?
A path traversal vulnerability, as seen in CVE-2014-3702, allows attackers to access directories and files that are outside the intended file structure.