CVE-2024-31849: Path Traversal
Published Apr 5, 2024
·Updated
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
Affected Software
1 affected component
CData CData Connect<23.4.8846
Event History
Apr 5, 2024
CVE Published
via MITRE·05:40 PM
Data Sourced
via MITRE·05:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Sep 17, 56274
Event
via FIRST·06:28 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-31849?
The severity of CVE-2024-31849 is considered high due to its potential for unauthorized administrative access.
2
How do I fix CVE-2024-31849?
To fix CVE-2024-31849, update CData Connect to version 23.4.8846 or later.
3
Who is affected by CVE-2024-31849?
CVE-2024-31849 affects all users of CData Connect versions prior to 23.4.8846 when using the embedded Jetty server.
4
What type of vulnerability is CVE-2024-31849?
CVE-2024-31849 is a path traversal vulnerability that allows for unauthorized access.
5
Can CVE-2024-31849 be exploited remotely?
Yes, CVE-2024-31849 can be exploited remotely by an unauthenticated attacker.