Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.
History

Thu, 26 Feb 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Severalnines
Severalnines clustercontrol
CPEs cpe:2.3:a:severalnines:clustercontrol:*:*:*:*:*:*:*:*
Vendors & Products Severalnines
Severalnines clustercontrol
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Aug 2024 20:45:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-07-26T00:00:00.000Z

Updated: 2024-08-06T20:31:53.543Z

Reserved: 2024-07-18T00:00:00.000Z

Link: CVE-2024-41628

cve-icon Vulnrichment

Updated: 2024-08-02T04:46:52.593Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-26T21:15:14.303

Modified: 2024-11-21T09:32:52.497

Link: CVE-2024-41628

cve-icon Redhat

No data.