First published: Thu Oct 16 2014(Updated: )
A path traversal flaw was found in eDeploy's session parameter handler. A remote attacker could use this flaw to create arbitrary directories on the server, potentially leading to a denial-of-service.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat eDeploy | =0.1.0 | |
redhat eDeploy | =0.2.0 | |
redhat eDeploy | =1.4.0 | |
redhat eDeploy | =1.5.0 | |
redhat eDeploy | =h.1.0.0 | |
redhat eDeploy | =h.1.1.0 | |
redhat eDeploy | =h.1.2.0 | |
redhat eDeploy | =h.1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3702 has a medium severity level due to its potential for creating arbitrary directories, leading to denial-of-service.
To fix CVE-2014-3702, you should upgrade to a patched version of Red Hat eDeploy that resolves this path traversal vulnerability.
CVE-2014-3702 affects versions 0.1.0, 0.2.0, 1.4.0, 1.5.0, h.1.0.0, h.1.1.0, h.1.2.0, and h.1.3.0 of Red Hat eDeploy.
Yes, CVE-2014-3702 can be exploited remotely by an attacker to create arbitrary directories on the server.
A path traversal vulnerability, as seen in CVE-2014-3702, allows attackers to access directories and files that are outside the intended file structure.