CVE-2024-25157: Authentication bypass in GoAnywhere MFT prior to 7.6.0
An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25157?
CVE-2024-25157 is considered a critical vulnerability as it allows unauthorized access and modification of sensitive information.
How do I fix CVE-2024-25157?
To fix CVE-2024-25157, upgrade GoAnywhere MFT to version 7.6.0 or later to resolve the authentication bypass issue.
What types of information can be accessed due to CVE-2024-25157?
Due to CVE-2024-25157, attackers may access or modify sensitive information that should be restricted based on user permissions.
Who is affected by CVE-2024-25157?
CVE-2024-25157 affects Admin Users of GoAnywhere MFT prior to version 7.6.0 with access to the Agent Console.
Is there a workaround for CVE-2024-25157?
Currently, the recommended approach for CVE-2024-25157 is to upgrade to the patched version, as there are no known effective workarounds.