Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2022-04-21T20:50:16.773718Z

Updated: 2024-09-16T20:43:36.814Z

Reserved: 2022-02-04T00:00:00

Link: CVE-2022-24424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-04-21T21:15:07.870

Modified: 2022-05-03T17:34:26.287

Link: CVE-2022-24424

cve-icon Redhat

No data.