CVE Vulnerabilities

CVE-2024-0204

Direct Request ('Forced Browsing')

Published: Jan 22, 2024 | Modified: Feb 02, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Authentication bypass in Fortras GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Goanywhere_managed_file_transfer Fortra 7.0.0 (including) 7.4.1 (excluding)
Goanywhere_managed_file_transfer Fortra 6.0.0 (including) 6.0.0 (including)

Potential Mitigations

References