← Back to browse · API

CVE-2024-31849

Severity
CRITICAL
CVSS
9.8
EPSS
0.06076
Risk score
41.33
CISA KEV
No
PoC
No
Published
2024-04-05
Modified
2024-08-02
First seen
2026-08-08
Aliases
EUVD-2024-29719, GHSA-F3HC-9Q6R-J846
Products
Tanium:Connect, Tanium:Connect 0 <23.4.8846
Sources
euvd EUVD-2024-29719

Description

A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.

References