cvelist/2023/45xxx/CVE-2023-45689.json

88 lines
3.3 KiB
JSON
Raw Normal View History

2023-10-10 20:00:34 +00:00
{
2023-10-16 17:00:37 +00:00
"data_version": "4.0",
2023-10-10 20:00:34 +00:00
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2023-45689",
2023-10-16 17:00:37 +00:00
"ASSIGNER": "cve@rapid7.com",
"STATE": "PUBLIC"
2023-10-10 20:00:34 +00:00
},
"description": {
"description_data": [
{
"lang": "eng",
2023-10-16 17:00:37 +00:00
"value": "Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal"
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
"cweId": "CWE-22"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "South River Technologies",
"product": {
"product_data": [
{
"product_name": "Titan MFT",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "0",
"version_value": "2.0.17.2298"
}
]
}
},
{
"product_name": "Titan SFTP",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "0",
"version_value": "2.0.17.2298"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/",
"refsource": "MISC",
"name": "https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/"
},
{
"url": "https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-issues-cve-2023-45685-through-cve-2023-45690",
"refsource": "MISC",
"name": "https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-issues-cve-2023-45685-through-cve-2023-45690"
2023-10-10 20:00:34 +00:00
}
]
2023-10-16 17:00:37 +00:00
},
"generator": {
"engine": "Vulnogram 0.1.0-dev"
},
"source": {
"discovery": "UNKNOWN"
2023-10-10 20:00:34 +00:00
}
}