Loading HuntDB...

Aviatrix Controller Unrestricted Upload of File

Added Jan. 18, 2022 Due Feb. 1, 2022 CVE-2021-40870
Overdue Aviatrix / Aviatrix Controller CWE-25 CWE-96

Description

Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
6 months ago