First published: Wed Aug 07 2024(Updated: )
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
<2.26.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37403 is considered a high severity vulnerability due to its potential to expose sensitive information.
CVE-2024-37403 allows malicious apps on the device to read sensitive data, exploiting the path traversal issue.
To mitigate CVE-2024-37403, users should update Ivanti Docs@Work to version 2.26.0 or later.
CVE-2024-37403 affects all versions of Ivanti Docs@Work for Android prior to 2.26.0.
Currently, there are no known workarounds for CVE-2024-37403 other than updating the application.