First published: Mon Nov 18 2024(Updated: )
Node.js could allow a remote attacker to bypass security restrictions, caused by the improper processing of UNC paths by the Permission Model. An attacker could exploit this vulnerability to lead to vulnerable edge cases.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Planning Analytics | <=2.1 | |
IBM Planning Analytics | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37372 is considered a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2024-37372, users should update IBM Planning Analytics to version 2.1 or later.
CVE-2024-37372 affects IBM Planning Analytics versions up to and including 2.1 and 2.0.
CVE-2024-37372 can be exploited by attackers through improper processing of UNC paths leading to potential security bypass.
CVE-2024-37372 is caused by the Permission Model's improper handling of paths that start with two backslashes.