CVE-2024-31850 is a critical path traversal vulnerability affecting CData Arc versions prior to 23.4.8839 when utilizing its embedded Jetty server. This flaw allows unauthenticated remote attackers to access sensitive information and perform limited actions. With a CVSS score of 8.6 (High) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector and low attack complexity. While not yet observed in active exploitation or listed in CISA's KEV catalog, public Nuclei templates exist, suggesting potential for future exploitation, though community discussion and media coverage remain low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 23.4.8839CPE match | cpe:2.3:a:cdata:arc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.