CVE Vulnerabilities

CVE-2024-1654

Permissive List of Allowed Inputs

Published: Mar 14, 2024 | Modified: Jan 23, 2025
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This vulnerability potentially allows unauthorized write operations which may lead to remote code execution. An attacker must already have authenticated admin access and knowledge of both an internal system identifier and details of another valid user to exploit this.

Weakness

The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.

Affected Software

Name Vendor Start Version End Version
Papercut_mf Papercut * 20.1.10 (excluding)
Papercut_mf Papercut 21.0.0 (including) 21.2.14 (excluding)
Papercut_mf Papercut 22.0.0 (including) 22.1.5 (excluding)
Papercut_mf Papercut 23.0.1 (including) 23.0.7 (excluding)
Papercut_ng Papercut * 20.1.10 (excluding)
Papercut_ng Papercut 21.0.0 (including) 21.2.14 (excluding)
Papercut_ng Papercut 22.0.0 (including) 22.1.5 (excluding)
Papercut_ng Papercut 23.0.1 (including) 23.0.7 (excluding)

References