
PEACH
Un cadre d’isolation des locataires
When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allow Fuzzing for application mapping. This issue affects GoAnywhere versions before 7.8.0. The vulnerability was discovered on August 2, 2023, and publicly disclosed on April 28, 2025 (Fortra Advisory, NVD).
The vulnerability is classified as CWE-209 (Generation of Error Message Containing Sensitive Information). It has been assigned a CVSS v3.1 base score of 3.5 LOW by Fortra (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N) and 4.3 MEDIUM by NIST (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). The issue occurs specifically when a Web User without Create permission attempts to upload a file to a non-existent directory, resulting in an error message that exposes the absolute server path (Fortra Advisory).
The vulnerability allows potential attackers to gain knowledge of the server's file system structure through the exposed absolute path information in error messages. This information disclosure could be used for application mapping and potentially assist in further attack planning (Fortra Advisory).
The primary mitigation is to upgrade to GoAnywhere version 7.8.0 or later. As a workaround, administrators can grant Create permission on Subfolders to Web Users, as this permission would automatically create non-existent directories during upload attempts, preventing the error message from occurring (Fortra Advisory).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."