CVE-2024-1221: Improper access controls on APIs on Linux and macOS in PaperCut NG/MF
This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affects Linux and macOS PaperCut NG/MF servers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1221?
CVE-2024-1221 has been classified as a medium severity vulnerability.
How do I fix CVE-2024-1221?
To fix CVE-2024-1221, update your PaperCut NG/MF to the latest version that addresses this vulnerability.
Which versions are affected by CVE-2024-1221?
CVE-2024-1221 affects certain versions of PaperCut NG/MF up to 23.0.7 for both Linux and macOS.
What impact does CVE-2024-1221 have on my PaperCut server?
CVE-2024-1221 may expose files on a PaperCut NG/MF server if exploited through a specifically crafted payload.
Is CVE-2024-1221 present on Windows installations of PaperCut?
No, CVE-2024-1221 specifically affects Linux and macOS installations of PaperCut, not Windows.