PT-2024-20252 · Unknown · Devan-Kerman Arrp

·

CVE-2024-24042

·

Published

2024-03-18

·

Updated

2024-08-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Devan-Kerman ARRP versions 0.8.1 and before
Description The issue allows a remote attacker to execute arbitrary code via the dumpDirect in RuntimeResourcePackImpl component. This enables the attacker to potentially access and manipulate files on the system, leading to unauthorized actions.
Recommendations For Devan-Kerman ARRP versions 0.8.1 and before, consider disabling the dumpDirect function in the RuntimeResourcePackImpl component as a temporary workaround until a patch is available. Restrict access to the RuntimeResourcePackImpl component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-24042
GHSA-CG24-JJR5-RXMF

Affected Products

Devan-Kerman Arrp