CVE-2024-29434: Alldata

High severity, CVSS 8.3. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.

Affected products

  • Alldata Alldata: version 0.4.6 only

Published 2024-04-02. Last modified 2026-06-17.