DSA-2022-070: Dell EMC AppSync Security Update for a Path Traversal Vulnerability
Oversigt: Dell EMC AppSync remediation is available for a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.
Denne artikel gælder for
Denne artikel gælder ikke for
Denne artikel er ikke knyttet til et bestemt produkt.
Det er ikke alle produktversioner, der er identificeret i denne artikel.
Virkning
High
Oplysninger
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24424 | Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24424 | Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Berørte produkter og udbedring
| Product | Affected Versions | Updated Versions | Link to Update | |
| Dell EMC AppSync | Versions 3.9.0.0 to 4.3.0.0 | 4.4.0.0 | https://dl.dell.com/downloads/DL107581 | |
| Product | Affected Versions | Updated Versions | Link to Update | |
| Dell EMC AppSync | Versions 3.9.0.0 to 4.3.0.0 | 4.4.0.0 | https://dl.dell.com/downloads/DL107581 | |
Revisionshistorik
| Revision | Date | Description |
| 1.0 | 2022-03-16 | Initial Release |
Relaterede oplysninger
Ansvarsfraskrivelse
Berørte produkter
AppSync, AppSync, Product Security InformationArtikelegenskaber
Artikelnummer: 000197433
Artikeltype: Dell Security Advisory
Senest ændret: 16 mar. 2022
Find svar på dine spørgsmål fra andre Dell-brugere
Supportservices
Kontrollér, om din enhed er dækket af supportservices.