A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.
History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-06-17T00:00:00

Updated: 2024-11-06T16:23:56.560Z

Reserved: 2024-06-16T00:00:00

Link: CVE-2024-38449

cve-icon Vulnrichment

Updated: 2024-08-02T04:12:24.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-17T19:15:58.567

Modified: 2024-11-21T09:25:54.520

Link: CVE-2024-38449

cve-icon Redhat

No data.