漏洞描述
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
my.goanywhere.comhttps://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml↗www.fortra.comhttps://www.fortra.com/security/advisory/fi-2024-001↗github.comhttps://github.com/horizon3ai/CVE-2024-0204/blob/main/CVE-2024-0204.py↗www.horizon3.aihttps://www.horizon3.ai/cve-2024-0204-fortra-goanywhere-mft-authentication-bypass-deep-dive/↗packetstormsecurity.comhttp://packetstormsecurity.com/files/176683/GoAnywhere-MFT-Authentication-Bypass.html↗