Aqua Drive, in its 2.4 version, is vulnerable to a...
High severity
Unreviewed
Published
Oct 4, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Oct 4, 2023
Published to the GitHub Advisory Database
Oct 4, 2023
Last updated
Apr 4, 2024
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible to access and modify the source and configuration files of the cloud disk platform, affecting the integrity and availability of the entire platform.
References