CVE-2024-27630: High severity gnu savane vulnerability
Published Apr 8, 2024
·Updated
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker to delete arbitrary files via crafted input to the trackersdatadeletefile function.
Affected Software
2 affected components
GNU Savane<3.12
GNU Savane<3.13
Event History
Apr 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-27630?
CVE-2024-27630 is considered a critical vulnerability due to its potential to allow remote attackers to delete arbitrary files.
2
How do I fix CVE-2024-27630?
To fix CVE-2024-27630, upgrade GNU Savane to version 3.13 or later, which addresses this vulnerability.
3
Who is affected by CVE-2024-27630?
CVE-2024-27630 affects all versions of GNU Savane up to and including 3.12.
4
What type of vulnerability is CVE-2024-27630?
CVE-2024-27630 is an Insecure Direct Object Reference (IDOR) vulnerability.
5
What can an attacker do with CVE-2024-27630?
An attacker can exploit CVE-2024-27630 to delete arbitrary files on the server by submitting crafted input.