CVE-2024-29309: Code Injection
Published May 2, 2024
·Updated
An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.
Affected Software
1 affected component
Alfresco Content Services
Event History
May 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-29309?
CVE-2024-29309 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-29309?
To fix CVE-2024-29309, update Alfresco Content Services to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2024-29309?
CVE-2024-29309 affects Alfresco Content Services version 23.3.0.7.
4
Can CVE-2024-29309 allow for data breaches?
Yes, CVE-2024-29309 can enable remote attackers to execute arbitrary code, potentially leading to data breaches.
5
What is the attack vector for CVE-2024-29309?
The attack vector for CVE-2024-29309 is the Transfer Service in Alfresco Content Services, which can be exploited remotely.