CVE-2024-6789: Path traversal in M-Files API
Published Aug 27, 2024
·Updated
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
Affected Software
2 affected components
M-Files M-Files server<24.2.13421.15
M-Files M-Files server<24.8.13981.0
Remediation
Information
Update to patched version
Event History
Aug 27, 2024
CVE Published
via MITRE·09:57 AM
Data Sourced
via MITRE·09:57 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-6789?
CVE-2024-6789 is a medium severity vulnerability that allows authenticated users to exploit a path traversal issue.
2
How do I fix CVE-2024-6789?
To fix CVE-2024-6789, upgrade your M-Files Server to version 24.8.13981.0 or later, or to LTS 24.2.13421.15 SR2 or later.
3
What versions of M-Files Server are affected by CVE-2024-6789?
CVE-2024-6789 affects M-Files Server versions before 24.8.13981.0 and LTS versions before 24.2.13421.15 SR2.
4
What type of vulnerability is CVE-2024-6789?
CVE-2024-6789 is classified as a path traversal vulnerability.
5
Who can exploit CVE-2024-6789?
CVE-2024-6789 can be exploited by authenticated users of the affected M-Files Server versions.