cvelist/2024/12xxx/CVE-2024-12632.json
2024-12-13 21:01:00 +00:00

76 lines
2.6 KiB
JSON

{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"CVE_data_meta": {
"ID": "CVE-2024-12632",
"ASSIGNER": "security-disclosures@huntresslabs.com",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "In Cleo Harmony up to and including 5.8.0.21, VLTrader up to and including 5.8.0.21, and LexiCom up to and including 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"cweId": "CWE-434"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Cleo",
"product": {
"product_data": [
{
"product_name": "Cleo Harmony, VLTrader, LexiCom",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "0",
"version_value": "5.8.0.21"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update",
"refsource": "MISC",
"name": "https://support.cleo.com/hc/en-us/articles/28408134019735-Cleo-Product-Security-Update"
},
{
"url": "https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild",
"refsource": "MISC",
"name": "https://www.huntress.com/blog/threat-advisory-oh-no-cleo-cleo-software-actively-being-exploited-in-the-wild"
}
]
},
"generator": {
"engine": "Vulnogram 0.2.0"
},
"source": {
"discovery": "UNKNOWN"
}
}