CVE-2024-37273: Path Traversal
Published Jun 4, 2024
·Updated
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
2 affected components
npm/@janhq/core<=0.1.11
Homebrew Jan=0.4.12
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 4, 2024
CVE Published
via NVD·07:20 PM
Advisory Published
via GitHub·09:32 PM
Aug 15, 2024
Data Sourced
via MITRE·01:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-37273?
CVE-2024-37273 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-37273?
To mitigate CVE-2024-37273, upgrade to Jan version 0.4.13 or later, which addresses this arbitrary file upload vulnerability.
3
What types of systems are affected by CVE-2024-37273?
CVE-2024-37273 affects Jan version 0.4.12 and earlier, specifically when using the /v1/app/appendFileSync interface.
4
What can attackers do exploiting CVE-2024-37273?
Attackers can exploit CVE-2024-37273 to upload malicious files that allow for arbitrary code execution on the server.
5
Is the vulnerability CVE-2024-37273 present in any npm packages?
Yes, CVE-2024-37273 is present in the npm package @janhq/core versions up to 0.1.11.