CVE-2024-31851: Cdata Sync
High severity, CVSS 8.6. EPSS: 2.9% chance of exploitation in the next 30 days.
A path traversal vulnerability exists in the Java version of CData Sync < 23.4.8843 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain access to sensitive information and perform limited actions.
Affected products
- Cdata Sync: before 23.4.8843 (fixed in 23.4.8843)
Published 2024-04-05. Last modified 2026-06-17.