CVE-2024-25156: Path traversal in GoAnywhere MFT 7.4.1 and Earlier
Published Mar 14, 2024
·Updated
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.
Affected Software
2 affected components
Fortra Goanywhere Managed File Transfer<7.4.2
HelpSystems GoAnywhere MFT<7.4.2
Event History
Mar 14, 2024
CVE Published
via MITRE·02:06 PM
Data Sourced
via MITRE·02:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25156?
CVE-2024-25156 is classified as a critical vulnerability due to its ability to bypass endpoint-specific permission checks.
2
How do I fix CVE-2024-25156?
To mitigate CVE-2024-25156, upgrade GoAnywhere MFT to version 7.4.2 or higher.
3
What versions are affected by CVE-2024-25156?
CVE-2024-25156 affects all versions of GoAnywhere MFT prior to 7.4.2.
4
What impact does CVE-2024-25156 have on security?
CVE-2024-25156 allows attackers to gain unauthorized access by circumventing important permission checks.
5
Is CVE-2024-25156 being actively exploited?
As of the latest information, there are no confirmed active exploits for CVE-2024-25156, but it poses a serious risk.