CVE-2024-52309
Last modified
CVE-2024-52309 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. One powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
SFTPGo is a full-featured and highly configurable SFTP, HTTP/S, FTP/S and WebDAV server - S3, Google Cloud Storage, Azure Blob. One powerful feature of SFTPGo is the ability to have the EventManager execute scripts or run applications in response to certain events. This feature is very common in all software similar to SFTPGo and is generally unrestricted. However, any SFTPGo administrator with permission to run a script has access to the underlying OS/container with the same permissions as the user running SFTPGo. This is unexpected for some SFTPGo administrators who think that there is a clear distinction between accessing the system shell and accessing the SFTPGo WebAdmin UI. To avoid this confusion, running system commands is disabled by default in 2.6.3, and an allow list has been added so that system administrators configuring SFTPGo must explicitly define which commands are allowed to be configured from the WebAdmin UI.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-52309?
How severe is CVE-2024-52309?
How do I fix CVE-2024-52309?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52303aiohttp is an asynchronous HTTP client/server framework for …8.7
- CVE-2024-52304aiohttp is an asynchronous HTTP client/server framework for …7.5
- CVE-2024-52305UnoPim is an open-source Product Information Management (PIM…4.8
- CVE-2024-52306FileManager provides a Backpack admin interface for files an…9.8
- CVE-2024-52307authentik is an open-source identity provider. Due to the us…5.6
- CVE-2024-52308The GitHub CLI version 2.6.1 and earlier are vulnerable to r…9.6
- CVE-2024-5231A vulnerability was found in Campcodes Complete Web-Based Sc…6.5
- CVE-2024-52311Authentication tokens issued via Cognito in data.all are not…6.3
- CVE-2024-52312Due to inconsistent authorization permissions, data.all may …5.4
- CVE-2024-52313An authenticated data.all user is able to manipulate a getDa…5.3
- CVE-2024-52314A data.all admin team member who has access to the customer-…6.9
- CVE-2024-52316Unchecked Error Condition vulnerability in Apache Tomcat. If…9.8
Are you affected by CVE-2024-52309?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
