CVE-2024-55466: Command Injection
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55466?
CVE-2024-55466 has been rated as a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-55466?
To fix CVE-2024-55466, upgrade to the latest version of ThingsBoard that addresses this arbitrary file upload vulnerability.
What products are affected by CVE-2024-55466?
CVE-2024-55466 affects ThingsBoard Community, ThingsBoard Cloud, and ThingsBoard Professional versions up to 3.8.1.
What kind of attack is possible with CVE-2024-55466?
CVE-2024-55466 allows attackers to execute arbitrary code on the server by uploading a crafted file.
Is CVE-2024-55466 easy to exploit?
Yes, CVE-2024-55466 can be easily exploited if proper file upload validation measures are not in place.