First published: Wed Mar 16 2022(Updated: )
Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC AppSync | >=3.9.0.0<4.4.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-24424 has been classified as a medium severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2022-24424, upgrade Dell EMC AppSync to version 4.4.0.0 or later.
CVE-2022-24424 can be exploited by remote unauthenticated attackers to perform path traversal attacks and access sensitive files.
Dell EMC AppSync versions from 3.9 to 4.3 are affected by CVE-2022-24424.
No, CVE-2022-24424 can be exploited by remote attackers without authentication.