Using GoAnywhere MFT for file transfers? Patch now – an exploit's out for a critical bug
ID: 67489847-a641-5924-9b30-79621a1d5c8c
STIX ID: report--67489847-a641-5924-9b30-79621a1d5c8c
Feed Name: The Register (Security)
Researchers published a working exploit for CVE-2024-0204, a critical (CVSS 9.8) authentication-bypass in Fortra GoAnywhere MFT that uses a Tomcat path-traversal (/..;/) against InitialAccountSetup.xhtml to create admin accounts; Fortra advises patching to >=7.4.1 or removing/replacing the setup file as mitigation. Although Greynoise and Fortra report no widespread exploitation yet, the public PoC and the product's use by government and critical infrastructure create a near-term high risk of e.g., ransomware or extortion attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
