漏洞描述
Fortra GoAnywhere MFT is susceptible to remote code execution via unsafe deserialization of an arbitrary attacker-controlled object. This stems from a pre-authentication command injection vulnerability in the License Response Servlet.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
frycos.github.iohttps://frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.html↗my.goanywhere.comhttps://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1↗infosec.exchangehttps://infosec.exchange/@briankrebs/109795710941843934↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2023-0669↗