Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a...
Critical severity
Unreviewed
Published
May 31, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
May 31, 2023
Published to the GitHub Advisory Database
May 31, 2023
Last updated
Apr 4, 2024
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the downstream node user. Exploitation of this issue does not require user interaction.
References