Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform.
References
Link | Resource |
---|---|
https://www.incibe.es/en/incibe-cert/notices/aviso/relative-path-traversal-aqua-esolutions | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-10-04T10:56:36.903Z
Updated: 2023-10-04T10:56:36.903Z
Reserved: 2023-07-17T07:36:44.415Z
Link: CVE-2023-3701
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-04T11:15:10.430
Modified: 2023-10-05T17:04:18.250
Link: CVE-2023-3701
JSON object: View
Redhat Information
No data.