CVE-2024-31849: Cdata Connect
Critical severity, CVSS 9.8. EPSS: 6.1% chance of exploitation in the next 30 days.
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the application.
Affected products
- Cdata Connect: before 23.4.8846 (fixed in 23.4.8846)
Published 2024-04-05. Last modified 2026-06-17.