CVE-2024-48019
published 2025-02-04CVE-2024-48019: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache…
PriorityP334medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.99%
58.5th percentile
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.
Application administrators can read arbitrary
files from the server filesystem through path traversal.
Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | doris | >= 2.1.0 < 2.1.8 | 2.1.8 |
| apache | doris | >= 3.0.0 < 3.0.3 | 3.0.3 |
| apache_software_foundation | apache_doris | >= 2.1.0 < 2.1.8 | 2.1.8 |
| apache_software_foundation | apache_doris | >= 3.0.0 < 3.0.3 | 3.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Cisco Data Center Network Manager Authentication Bypass Inbound (CVE-2019-15976)
suricata·2021-07-24·CVSS 9.8
CVE-2019-15976 [CRITICAL] ET EXPLOIT Cisco Data Center Network Manager Authentication Bypass Inbound (CVE-2019-15976)
ET EXPLOIT Cisco Data Center Network Manager Authentication Bypass Inbound (CVE-2019-15976)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco Data Center Network Manager Authentication Bypass Inbound (CVE-2019-15976)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/DbAdminWSService/DbAdminWS"; fast_pattern; http.request_body; content:""; content:""; content:""; reference:url,www.exploit-db.com/exploits/48019; reference:cve,2019-15976; classtype:attempted-admin; sid:2033409; rev:2; metadata:created_at 2021_07_24, cve CVE_2019_15976, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0001, mitre_tactic_name In
Suricata
ET EXPLOIT Cisco Data Center Network Manager Directory Traversal Inbound (CVE-2019-15980)
suricata·2021-07-24·CVSS 7.2
CVE-2019-15980 [HIGH] ET EXPLOIT Cisco Data Center Network Manager Directory Traversal Inbound (CVE-2019-15980)
ET EXPLOIT Cisco Data Center Network Manager Directory Traversal Inbound (CVE-2019-15980)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Cisco Data Center Network Manager Directory Traversal Inbound (CVE-2019-15980)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/ReportWSService/ReportWS"; fast_pattern; http.request_body; content:"..|2f|..|2f|"; reference:url,www.exploit-db.com/exploits/48019; reference:cve,2019-15980; classtype:attempted-admin; sid:2033412; rev:2; metadata:created_at 2021_07_24, cve CVE_2019_15980, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_11_26, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_tec
No public exploits indexed.
No writeups or analysis indexed.
2025-02-04
Published