CVE-2024-4040
CrushFTP vulnerability analysis and mitigation

Summary

CrushFTP recently released version 11.1.0 and highlighted that earlier versions below 11.1.0 and 10.7.1 contain a vulnerability permitting users to escape their VFS and download system files. This security flaw was assigned CVE-2024-4040 on April 22, 2024. Users are advised to upgrade to the latest version of CrushFTP.

Technical details

The public advisory from CrushFTP describes the issue as a VFS sandbox escape that permits low-privileged remote attackers to read files beyond the intended limits of the VFS Sandbox in its file transfer software. Researchers further analyzed the vulnerability and concluded that it can be exploited without authentication and with minimal technical effort. According to their research, this vulnerability allows attackers not only to read files at the root level but also to bypass authentication mechanisms for administrator accounts and execute code remotely. Although officially recorded as an arbitrary file read, the vulnerability might be more accurately termed as a server-side template injection (SSTI). The vulnerability, CVE-2024-4040, has been observed being exploited in the wild.

Affected products

CrushFTP in versions before 10.7.1 and 11.0 before 11.1.0 are vulnerable to CVE-2024-4040.

Remediation

It is advised to upgrade to versions 10.7.1 or 11.1.0.

References


SourceWiz Research

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management