CVE-2024-5865

V

ulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulnerability allowing arbitrary files reading outside the web publish directory. Versions 23.1-HF7 and on have the patch.

Configurations

Configuration 1 (hide)

cpe:2.3:a:delinea:privileged_access_service:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:48

Type Values Removed Values Added
References () https://github.com/klsecservices/Advisories/blob/master/K-Delinea-2023-001.md - Third Party Advisory () https://github.com/klsecservices/Advisories/blob/master/K-Delinea-2023-001.md - Third Party Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 7.7

29 Aug 2024, 20:26

Type Values Removed Values Added
CPE cpe:2.3:a:delinea:privileged_access_service:*:*:*:*:*:*:*:*
CWE CWE-22
References () https://github.com/klsecservices/Advisories/blob/master/K-Delinea-2023-001.md - () https://github.com/klsecservices/Advisories/blob/master/K-Delinea-2023-001.md - Third Party Advisory
CVSS v2 : unknown
v3 : 7.7
v2 : unknown
v3 : 6.5
First Time Delinea privileged Access Service
Delinea
Summary
  • (es) Vulnerabilidad en Delinea Centrify PAS v. 21.3 y posiblemente otros. La aplicación es propensa a sufrir una vulnerabilidad de path traversal que permite la lectura de archivos arbitrarios fuera del directorio de publicación web. Las versiones 23.1-HF7 y posteriores tienen el parche.

02 Jul 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-02 16:15

Updated : 2024-11-21 09:48


NVD link : CVE-2024-5865

Mitre link : CVE-2024-5865

CVE.ORG link : CVE-2024-5865


JSON object : View

CWE
CWE-26

Path Traversal: '/dir/../filename'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')