NONE · 0

CVE-2024-12019

The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read...

Vulnerability Description

The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read’ and ‘download’ privileges on at least one existing document in the application is required to exploit the vulnerability. Exploitation of this vulnerability would allow an attacker to read the contents of any file available within the privileges of the system user running the application.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-12019?

CVE-2024-12019 is a documented vulnerability. The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read the contents of files on the underlying operating system. An account with ‘read...

How severe is CVE-2024-12019?

CVSS scoring is not yet available for CVE-2024-12019. Check NVD for updates.

Is there a patch for CVE-2024-12019?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.