Description
Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .
Published: 2026-09-30
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Remote File Read
Action: Patch Today
AI Analysis

Impact

The vulnerability is an arbitrary file read exposed in the /api/model_report/file/download endpoint of Inspur Haiyue HCM Cloud. Unvalidated query parameters index and ext allow attackers to supply a traversal path such as /api/model_report/file/download?index=/&ext=../../../../etc/passwd to read any file on the server. This enables unauthenticated external users to access sensitive files, including system passwords, application database contents, and configuration data, thereby compromising confidentiality and potentially exposing credentials for further attacks.

Affected Systems

The affected product is Inspur Haiyue HCM Cloud. No specific version information is disclosed; the issue is present in all currently deployed instances that expose the vulnerable endpoint.

Risk and Exploitability

The CVSS score of 8.7 categorises the flaw as high severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. The flaw can be exploited by an unauthenticated attacker via a crafted HTTP request from the internet, making it a straightforward path‑traversal attack with no additional privileges required. Exploitation evidence was reported by Shadowserver Foundation on 2024-11-04.

Generated by OpenCVE AI on September 30, 2026 at 21:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or upgrade to the latest version of Inspur Haiyue HCM Cloud that removes the unvalidated index and ext parameters in the file/download API.
  • If a patch is not yet available, restrict external access to the /api/model_report/file/download endpoint using firewall rules or reverse‑proxy configuration, limiting requests to trusted internal networks.
  • Enable logging for all API calls and monitor for abnormal usage patterns of the file/download endpoint, such as repeated use of traversal characters in the ext or index parameters.
  • Consider temporarily disabling the file/download API if immediate remediation cannot be achieved, until a patch is applied.

Generated by OpenCVE AI on September 30, 2026 at 21:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 .
Title Inspur HCM Cloud Arbitrary File Read via file/download Endpoint
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T20:24:25.915Z

Reserved: 2026-09-30T20:23:27.785Z

Link: CVE-2024-58387

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T21:16:52.510

Modified: 2026-09-30T21:16:52.510

Link: CVE-2024-58387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:00:16Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')