PT-2023-28880 · Croc · Croc

·

CVE-2023-43619

·

Publicado

2023-09-19

·

Atualizado

2024-09-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Croc versions through 9.6.5
Description An issue was discovered in Croc where a sender may send dangerous new files to a receiver, such as executable content or a .ssh/authorized keys file.
Recommendations For Croc versions through 9.6.5, update to version 9.6.16 or later to resolve the issue. As a temporary workaround, consider restricting the types of files that can be sent through Croc to minimize the risk of exploitation. Avoid using Croc to transfer executable content or sensitive files like .ssh/authorized keys until the issue is resolved.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-43619
GHSA-PPJH-XP5V-46WC
GO-2023-2073

Produtos afetados

Croc