DSA-2022-070: Dell EMC AppSync Security Update for a Path Traversal Vulnerability
요약: Dell EMC AppSync remediation is available for a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.
이 문서는 다음에 적용됩니다.
이 문서는 다음에 적용되지 않습니다.
이 문서는 특정 제품과 관련이 없습니다.
모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.
영향
High
세부 정보
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24424 | Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-24424 | Dell EMC AppSync versions from 3.9 to 4.3 contain a path traversal vulnerability in AppSync server. A remote unauthenticated attacker may potentially exploit this vulnerability to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application. | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
영향을 받는 제품 및 문제 해결
| Product | Affected Versions | Updated Versions | Link to Update | |
| Dell EMC AppSync | Versions 3.9.0.0 to 4.3.0.0 | 4.4.0.0 | https://dl.dell.com/downloads/DL107581 | |
| Product | Affected Versions | Updated Versions | Link to Update | |
| Dell EMC AppSync | Versions 3.9.0.0 to 4.3.0.0 | 4.4.0.0 | https://dl.dell.com/downloads/DL107581 | |
개정 내역
| Revision | Date | Description |
| 1.0 | 2022-03-16 | Initial Release |
관련 정보
법적 고지 사항
해당 제품
AppSync, AppSync, Product Security Information문서 속성
문서 번호: 000197433
문서 유형: Dell Security Advisory
마지막 수정 시간: 16 3월 2022
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.