CVE-2024-52010

CVSS 3.1 Score 0.0 of 10 (low)

Details

Published Nov 12, 2024
Updated: Nov 13, 2024
CWE ID 78

Summary

CVE-2024-52010 is a newly identified vulnerability affecting Zoraxy, an HTTP reverse proxy and forwarding tool. This issue lies in the Web SSH feature, where an authenticated attacker can exploit a command injection vulnerability in the HandleCreateProxySession function. By manipulating the username variable, an adversary can escape the bash command and inject arbitrary commands, effectively gaining root access to the host system. The vulnerability arises due to insufficient validation and sanitization of the username input.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share