Description
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29808 | It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endpoint does not have any input validation of the user's input that allows a malicious payload to be injected. |
References
History
No history.
Status: PUBLISHED
Assigner: GovTech CSG
Published:
Updated: 2024-09-16T17:09:18.135Z
Reserved: 2021-10-25T00:00:00.000Z
Link: CVE-2021-42853
No data.
Status : Modified
Published: 2022-03-10T17:44:06.360
Modified: 2024-11-21T06:28:13.813
Link: CVE-2021-42853
No data.
OpenCVE Enrichment
No data.
EUVD