First published: Thu Mar 14 2024(Updated: )
A path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in the GoAnywhere Admin and Web Clients.
Credit: df4dee71-de3a-4139-9588-11b62fe6c0ff
Affected Software | Affected Version | How to fix |
---|---|---|
HelpSystems GoAnywhere Managed File Transfer | <7.4.2 | |
Fortra GoAnywhere Managed File Transfer | <7.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25156 is classified as a critical vulnerability due to its ability to bypass endpoint-specific permission checks.
To mitigate CVE-2024-25156, upgrade GoAnywhere MFT to version 7.4.2 or higher.
CVE-2024-25156 affects all versions of GoAnywhere MFT prior to 7.4.2.
CVE-2024-25156 allows attackers to gain unauthorized access by circumventing important permission checks.
As of the latest information, there are no confirmed active exploits for CVE-2024-25156, but it poses a serious risk.