CRITICAL
Path Traversal vulnerability via File Uploads in Genie
Published May 10, 2024
9.9
CRITICALCVSS 3.1
EPSS 24.63%
Description
A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18
Affected products
-
- Version 0StatusaffectedConstraints<=4.3.18
- Version
No data.
-
- Version 0StatusaffectedConstraints<4.3.18
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-1837 Advisory
- https://github.com/Netflix/genie/commit/6bad017d8078c94e80d6c6fe8abd693910bf55cf
- https://github.com/Netflix/genie/pull/1217
- https://github.com/Netflix/genie/releases/tag/v4.3.18
- https://github.com/Netflix/genie/security/advisories/GHSA-wpcv-5jgp-69f3
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2024-001.md
- https://github.com/advisories/GHSA-wpcv-5jgp-69f3 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-4701
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner netflix
Published May 10, 2024
Updated Aug 1, 2024
Reserved May 9, 2024
Link CVE-2024-4701
CISA Vulnrichment
Updated May 15, 2024
ENISA EUVD
EUVD-2024-1837 GHSA-WPCV-5JGP-69F3 Assigner netflix
Published May 10, 2024
Updated Aug 1, 2024
Exploited since n/a
Link EUVD-2024-1837