Home

Description

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

PUBLISHED Reserved 2023-10-20 | Published 2023-12-19 | Updated 2024-09-04 | Assigner hackerone




HIGH: 7.2CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Product status

Default status
unaffected

6.4.1 (semver)
affected

References

download.wavelink.com/.../avalanche_v6.4.2_release_notes.txt

download.wavelink.com/.../avalanche_v6.4.2_release_notes.txt

cve.org (CVE-2023-46264)

nvd.nist.gov (CVE-2023-46264)

Download JSON