CVE-2024-31851: Path Traversal
Published Apr 5, 2024
·Updated
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
Affected Software
1 affected component
CData Sync<23.4.8843
Event History
Apr 5, 2024
CVE Published
via MITRE·05:43 PM
Data Sourced
via MITRE·05:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Sep 17, 56274
Event
via FIRST·06:21 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-31851?
CVE-2024-31851 has a medium severity rating as it allows unauthenticated remote attackers to access sensitive information.
2
How do I fix CVE-2024-31851?
To fix CVE-2024-31851, upgrade CData Sync to version 23.4.8843 or later.
3
What type of vulnerability is CVE-2024-31851?
CVE-2024-31851 is classified as a path traversal vulnerability.
4
Who is affected by CVE-2024-31851?
CVE-2024-31851 affects users of CData Sync versions prior to 23.4.8843 when using the embedded Jetty server.
5
Can CVE-2024-31851 be exploited remotely?
Yes, CVE-2024-31851 can be exploited by an unauthenticated remote attacker.