DSA-2024-189: Security Update for Dell Repository Manager Vulnerability
Resumen: Dell Repository Manager remediation is available for a Path Traversal vulnerability in API module that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a
Este artículo no se aplica a
Este artículo no está vinculado a ningún producto específico.
No se identifican todas las versiones del producto en este artículo.
Impacto
High
Detalles
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-28976 | Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the privileges of the running web application. | 8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-28976 | Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API module. A local attacker with low privileges could potentially exploit this vulnerability to gain unauthorized write access to the files stored on the server filesystem with the privileges of the running web application. | 8.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Corrección y productos afectados
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell Repository Manager | Versions prior to 3.4.5 | 3.4.5 | Dell Repository Manager, v3.4.5 | Driver Details | Dell US |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell Repository Manager | Versions prior to 3.4.5 | 3.4.5 | Dell Repository Manager, v3.4.5 | Driver Details | Dell US |
No action required from the customer if DRM-3.4.5 is already installed either by the customer. However, we recommend following the workaround mentioned above.
Soluciones alternativas y mitigaciones
| CVE ID | Workaround and Mitigation |
|---|---|
| CVE-2024-28976 | Restrict the upload of unwanted files by incorporating additional input validation. |
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-04-23 | Initial release |
Reconocimientos
Dell would like to thank Jakub Brzozowski (redfr0g) for reporting this issue.
Información relacionada
Descargo de responsabilidad
Productos afectados
Dell Repository Manager Version 2.1, Dell Repository Manager Version 2.2, Dell Repository Manager Version 1.0, Dell Repository Manager Version 1.1, Dell Repository Manager Version 1.2, Dell Repository Manager Version 1.3
, Dell Repository Manager Version 1.4, Dell Repository Manager Version 1.5, Dell Repository Manager Version 1.6, Dell Repository Manager Version 1.7, Dell Repository Manager Version 1.8, Dell Repository Manager Version 1.9, Dell Repository Manager Version 2.0
...
Propiedades del artículo
Número del artículo: 000224412
Tipo de artículo: Dell Security Advisory
Última modificación: 23 abr 2024
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.