← Back to browse · API

CVE-2024-31848

Severity
CRITICAL
CVSS
9.8
EPSS
0.08086
Risk score
42.03
CISA KEV
No
PoC
No
Published
2024-04-05
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-29718, GHSA-CJGJ-QV8V-FHGH
Products
CData:API Server, CData:API Server 0 <23.4.8844
Sources
euvd EUVD-2024-29718

Description

A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

References