CVE-2024-2053
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 44.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the "www-data" user.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 44.58% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-23
- Affected
- articatech/artica proxy
- Source
- cve@takeonme.org
References
- http://seclists.org/fulldisclosure/2024/Mar/11Exploit, Mailing List
- https://korelogic.com/Resources/Advisories/KL-001-2024-001.txtExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/11Exploit, Mailing List
- https://korelogic.com/Resources/Advisories/KL-001-2024-001.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.