### [CVE-2024-31850](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-31850) ![](https://img.shields.io/static/v1?label=Product&message=Arc&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%2023.4.8839%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-22%20Improper%20Limitation%20of%20a%20Pathname%20to%20a%20Restricted%20Directory%20('Path%20Traversal')&color=brighgreen) ### Description A path traversal vulnerability exists in the Java version of CData Arc < 23.4.8839 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions. ### POC #### Reference - https://www.tenable.com/security/research/tra-2024-09 #### Github - https://github.com/Stuub/CVE-2024-31848-PoC