Impact
A path traversal flaw (CWE-22) exists in the Git Service component used by Altium Enterprise Server and Altium 365. The service processes a series of post‑clone file‑manipulation operations that include user‑supplied file paths without validation, allowing an authenticated user who has basic git read/write access to move files outside the intended repository boundaries. By placing a malicious script into a directory that the service later executes, the attacker can gain remote code execution under the Git Service account. In multi‑tenant Altium 365 instances, this flaw could also expose data belonging to other node. The vulnerability also allows the execution of arbitrary code (CWE-94) by injecting scripts that are later parsed and run by the service.
Affected Systems
Vulnerable deployments include Altium 365 and Altium Enterprise Server. All versions of Altium Enterprise Server prior to 8.1.1 are affected; the 8.1.1 release and later contain the fix. The issue also exists in Altium 365 until the service‑level remediation is applied, which has been rolled out to all shared multi‑tenant deployments. There is no specific product version information for Altium 365 beyond the service‑level patch.
Risk and Exploitability
The flaw has a CVSS base score of 9.4, indicating a very high severity. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is a credentialed vulnerability, requiring an authenticated user with basic git access to perform the malicious file moves. Attack Service account, and in shared multi‑tenant environments they may also obtain data from other tenants. Although exploitation requires legitimate credentials, the high severity and potential for lateral movement make this a considerable risk for affected environments.
OpenCVE Enrichment