CVE-2024-36267: Path Traversal
Path traversal vulnerability exists in Redmine DMSF Plugin versions prior to 3.1.4. If this vulnerability is exploited, a logged-in user may obtain or delete arbitrary files on the server (within the privilege of the Redmine process).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36267?
CVE-2024-36267 is considered a critical severity vulnerability due to its potential to allow unauthorized file access and deletion.
How do I fix CVE-2024-36267?
To resolve CVE-2024-36267, update the Redmine DMSF Plugin to version 3.1.4 or later.
Who is affected by CVE-2024-36267?
Users of Redmine DMSF Plugin versions prior to 3.1.4 are affected by CVE-2024-36267.
What type of attacks can exploit CVE-2024-36267?
CVE-2024-36267 can be exploited through path traversal attacks, allowing a logged-in user to access or delete sensitive files.
Is CVE-2024-36267 fixed in newer versions of Redmine DMSF Plugin?
Yes, CVE-2024-36267 is fixed in version 3.1.4 and subsequent releases of the Redmine DMSF Plugin.