High8.4
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L

PT-2024-53: Reading arbitrary files via API in PT Application Inspector (PT AI)

Error type:

  • CWE-36:Absolute Path Traversal

Vulnerability vector:

  • Base vulnerability score (CVSSv3.1): CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Severity (CVSSv3.1): 8.2 (high)
  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L
  • Severity (CVSSv4.0): 8.4 (high)

Description:

The vulnerability was identified in PT Application Inspector (PT AI), versions 4.4.0 - 4.9.0 inlusevely.

The discovered vulnerability allows an attacker with network access to PT AI to read source code files of other users' projects. The vulnerability can be used for privilege escalation.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 20.12.2024

Recommendations:

  • Update to version 4.9.1 or higher

Additional information: 

Researcher: Dmitry Kuramin (Jet Infosystems)

Identifiers:

BDU:2024-11475

Vendor:

Positive Technologies

Vulnerable product:

PT Application Inspector (PT AI)

Vulnerable versions:

4.4.0 - 4.9.0