Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Progress WS_FTP Server
Published Aug 28, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.69%
Description
In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Web Transfer Module allows File Discovery, Probe System Files, User-Controlled Filename, Path Traversal.
An authenticated file download flaw has been identified where a user can craft an API call that allows them to download a file from an arbitrary folder on the drive where that user host's root folder is located (by default this is C:)
Affected products
-
- Version 0StatusaffectedConstraints<8.8.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress Software Corporation | WS FTP Server | unaffected |
|
- < 8.8.8
-
- Version 0StatusaffectedConstraints<8.8.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress | WS Ftp Server | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-August-2024 vendor-advisoryVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48621 Advisory
- https://www.progress.com/ftp-server product
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-August-2024 | vendor-advisoryVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48621 | Advisory | |
| https://www.progress.com/ftp-server | product |
Change history (0)
No recorded changes yet.