The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
History

Mon, 18 Nov 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Trcore
Trcore dvc
CPEs cpe:2.3:a:trcore:dvc:*:*:*:*:*:*:*:*
Vendors & Products Trcore
Trcore dvc
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 Nov 2024 07:00:00 +0000

Type Values Removed Values Added
Description The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploading webshells.
Title TRCore DVC - Arbitrary File Upload through Path Traversal
Weaknesses CWE-23
CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2024-11-18T06:47:31.052Z

Updated: 2024-11-18T14:07:52.977Z

Reserved: 2024-11-18T01:44:56.599Z

Link: CVE-2024-11315

cve-icon Vulnrichment

Updated: 2024-11-18T13:57:51.633Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-18T07:15:16.673

Modified: 2024-11-18T17:11:17.393

Link: CVE-2024-11315

cve-icon Redhat

No data.