CVE-2024-38449
Last modified
CVE-2024-38449 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.. EPSS estimates a 0.96% chance of exploitation in the next 30 days.
Description
A Directory Traversal vulnerability in KasmVNC 1.3.1.230e50f7b89663316c70de7b0e3db6f6b9340489 and possibly earlier versions allows remote authenticated attackers to browse parent directories and read the content of files outside the scope of the application.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-38449?
How severe is CVE-2024-38449?
How do I fix CVE-2024-38449?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-38440Netatalk before 3.2.1 has an off-by-one error, and resultant…7.5
- CVE-2024-38441Netatalk before 3.2.1 has an off-by-one error and resultant …9.8
- CVE-2024-38443C/sorting/binary_insertion_sort.c in The Algorithms - C thro…6.2
- CVE-2024-38446NATO NCI ANET 3.4.1 mishandles report ownership. A user can …6.5
- CVE-2024-38447NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference …8.1
- CVE-2024-38448htags in GNU Global through 6.6.12 allows code execution in …9.1
- CVE-2024-3845Inappropriate implementation in Networks in Google Chrome pr…4.3
- CVE-2024-38453The Avalara for Salesforce CPQ app before 7.0 for Salesforce…7.5
- CVE-2024-38454ExpressionEngine before 7.4.11 allows XSS.6.1
- CVE-2024-38456HIGH-LEIT V05.08.01.03 and HIGH-LEIT V04.25.00.00 to 4.25.01…7.8
- CVE-2024-38457Xenforo before 2.2.16 allows CSRF.8.8
- CVE-2024-38458Xenforo before 2.2.16 allows code injection.8.8
Are you affected by CVE-2024-38449?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
