Sploitus

CVE-2024-0204

10 known exploits for CVE-2024-0204

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

Affected products
Goanywhere Mft
Fortra Goanywhere Managed File Transfer
< 7.4.1, 6.0.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
95.1% (100th percentile)
Weakness
CWE-425
NVD status
Modified
Published
2024-01-22
Attack patterns
CAPEC-1
Entry point
j_id_u:creteAdminGrid:username path
Path
/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml

Fix

Upgrade to version 7.4.1 or higher. The vulnerability may also be eliminated in non-container deployments by deleting the InitialAccountSetup.xhtml file in the install directory and restarting the services. For container-deployed instances, replace the file with an empty file and restart. For additional information, see  https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml  (registration required). https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml

Workaround

Users are encouraged to apply defense-in-depth tactics to limit access to the administrative console. Do not expose the console to the internet and apply web application controls such as a WAF, monitoring, and access controls.

CVE-2024-0204 at NVD
Authoritative description, scoring and affected products

10 known exploits for CVE-2024-0204

Proof-of-concept code and exploit modules indexed by Sploitus