A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 06 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-06T16:23:56.560Z

Reserved: 2024-06-16T00:00:00

Link: CVE-2024-38449

cve-icon Vulnrichment

Updated: 2024-08-02T04:12:24.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-17T19:15:58.567

Modified: 2024-11-21T09:25:54.520

Link: CVE-2024-38449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.