Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f4c-2q4h-c97w

Опубликовано: 05 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.2

Описание

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.

EPSS

Процентиль: 13%
0.00043
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 4.2
nvd
2 месяца назад

An Improper Access Control in the SFTP service in Fortra's GoAnywhere MFT prior to version 7.9.0 allows Web Users with an Authentication Alias and a valid SSH key but limited to Password authentication for SFTP to still login using their SSH key.

EPSS

Процентиль: 13%
0.00043
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-732