PT-2024-29: Path Traversal in Passwork
Vendor: Passwork
Vulnerable product: Passwork
Vulnerable version: 6.4.0
Vulnerability type:
• CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Identifier (ID):
• BDU:2024-08018
Vulnerability vector:
• Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
• Severity (CVSSv3.1): 7.6(high)
• Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
• Severity (CVSSv4.0): 7.2(high)
Description:
The vulnerability was identified in Passwork version 6.4.0.
The discovered vulnerability can be exploited by an attacker to gain access to local files and directories on the server, which are not avaliable by the logic of the application.
Vulnerability status: Confirmed by vendor
Date of vulnerability remediation: 09.10.2024
Recommendations:
• Update to version 6.4.3 or higher
Additional information: Oleg Surnin (Positive Technologies)