CVE-2024-5017: WhatsUp Gold AppProfileImport path traversal vulnerability
Published Jun 25, 2024
·Updated
In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenticated HTTP request to AppProfileImport can lead can lead to information disclosure.
Affected Software
1 affected component
Progress WhatsUp Gold<23.1.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WhatsUp Gold AppProfileImportto a version that resolves this vulnerability.Fixed in 2023.1.3
Event History
Jun 25, 2024
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-5017?
CVE-2024-5017 has been categorized as a medium severity vulnerability.
2
How do I fix CVE-2024-5017?
To fix CVE-2024-5017, upgrade to WhatsUp Gold version 2023.1.3 or later.
3
What kind of attack does CVE-2024-5017 facilitate?
CVE-2024-5017 facilitates information disclosure through a path traversal technique.
4
Is authentication required to exploit CVE-2024-5017?
No, CVE-2024-5017 can be exploited via unauthenticated HTTP requests.
5
Which versions of WhatsUp Gold are affected by CVE-2024-5017?
CVE-2024-5017 affects WhatsUp Gold versions prior to 2023.1.3.