CVE-2024-25294: SSRF
An SSRF issue in REBUILD v.3.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the FileDownloader.java, proxyDownload,URL parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25294?
CVE-2024-25294 is classified as a high severity vulnerability due to its potential for remote code execution and sensitive data exposure.
How do I fix CVE-2024-25294?
To fix CVE-2024-25294, update your REBUILD software to version 3.5.1 or later, which includes patches for this vulnerability.
What type of vulnerability is CVE-2024-25294?
CVE-2024-25294 is an SSRF (Server-Side Request Forgery) vulnerability that allows attackers to exploit the FileDownloader.java functionality.
What software is affected by CVE-2024-25294?
CVE-2024-25294 affects REBUILD version 3.5.0, allowing exploitation through specific URL parameters.
Can CVE-2024-25294 lead to data theft?
Yes, CVE-2024-25294 can allow attackers to obtain sensitive information from the server, posing a risk of data theft.