An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification.
Metrics
Affected Vendors & Products
References
History
Mon, 19 Aug 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-287 | |
CPEs | cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:* |
Thu, 15 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fortra
Fortra goanywhere Managed File Transfer |
|
CPEs | cpe:2.3:a:fortra:goanywhere_managed_file_transfer:-:*:*:*:*:*:*:* | |
Vendors & Products |
Fortra
Fortra goanywhere Managed File Transfer |
|
Metrics |
ssvc
|
Wed, 14 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permission checks when attempting to visit other pages. This could lead to unauthorized information disclosure or modification. | |
Title | Authentication bypass in GoAnywhere MFT prior to 7.6.0 | |
Weaknesses | CWE-303 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Fortra
Published: 2024-08-14T15:04:10.987Z
Updated: 2024-08-29T03:55:30.276Z
Reserved: 2024-02-06T21:23:57.925Z
Link: CVE-2024-25157
Vulnrichment
Updated: 2024-08-15T13:43:34.116Z
NVD
Status : Analyzed
Published: 2024-08-14T15:15:18.023
Modified: 2024-08-19T18:57:58.657
Link: CVE-2024-25157
Redhat
No data.