Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-42516 Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 15 Nov 2024 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:clinical-genomics:scout:*:*:*:*:*:*:*:*

Mon, 30 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Clinical-genomics
Clinical-genomics scout
CPEs cpe:2.3:a:clinical-genomics:scout:-:*:*:*:*:*:*:*
Vendors & Products Clinical-genomics
Clinical-genomics scout
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
Description Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.
Title Scout contains insufficient output escaping of attachment names
Weaknesses CWE-116
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-30T16:31:07.889Z

Reserved: 2024-09-25T21:46:10.929Z

Link: CVE-2024-47531

cve-icon Vulnrichment

Updated: 2024-09-30T16:31:02.300Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-30T16:15:09.750

Modified: 2024-11-15T18:02:14.250

Link: CVE-2024-47531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.