CVE-2024-36858: Malicious File Upload
An arbitrary file upload vulnerability in the /v1/app/writeFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36858?
CVE-2024-36858 is considered to be a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-36858?
To fix CVE-2024-36858, upgrade to Jan version 0.4.13 or later, where the vulnerability has been patched.
What types of applications are affected by CVE-2024-36858?
CVE-2024-36858 affects applications using Jan version 0.4.12 as well as versions of the @janhq/core package up to and including 0.1.11.
What is the impact of exploiting CVE-2024-36858?
Exploiting CVE-2024-36858 allows attackers to upload arbitrary files, leading to potential code execution on the affected server.
Is there a workaround for CVE-2024-36858?
As of now, the best course of action is to upgrade to the patched version, as there are no specific workarounds to mitigate the vulnerability.