High7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

PT-2024-29: Path Traversal in Passwork

PT-2024-29: Path Traversal in Passwork

Vendor: Passwork

Vulnerable product: Passwork

Vulnerable version: 6.4.0

Vulnerability type:

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Identifier (ID):

BDU:2024-08018

Vulnerability vector:

Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

Severity (CVSSv3.1): 7.6(high)

Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Severity (CVSSv4.0): 7.2(high)

Description:

The vulnerability was identified in Passwork version 6.4.0.

The discovered vulnerability can be exploited by an attacker to gain access to local files and directories on the server, which are not avaliable by the logic of the application.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 09.10.2024

Recommendations:

Update to version 6.4.3 or higher

Additional information: Oleg Surnin (Positive Technologies)