aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-32347 aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.
Fixes

Solution

Update to eHRD 6.8.1039V1055 or later version Update to eHRD 7.0.1141V422 or later version Update to eHRD 7.1.1033V429 or later version Update to eHRD 7.2.1061V36 or later version


Workaround

No workaround given by the vendor.

History

Tue, 08 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Aenrich
Aenrich a\+hrd
CPEs cpe:2.3:a:aenrich:a\+hrd:6.8:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.0:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.1:*:*:*:*:*:*:*
cpe:2.3:a:aenrich:a\+hrd:7.2:*:*:*:*:*:*:*
Vendors & Products Aenrich
Aenrich a\+hrd

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-08-01T20:20:01.574Z

Reserved: 2024-04-15T01:56:14.581Z

Link: CVE-2024-3775

cve-icon Vulnrichment

Updated: 2024-08-01T20:20:01.574Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-15T04:15:16.137

Modified: 2025-04-08T16:30:51.500

Link: CVE-2024-3775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.