CData API Server Security Update Advisory

Overview

 

We have released an update to address a vulnerability in the CData suite. users of affected versions are advised to update to the latest version.

 

Affected Products

 

CData API Server versions prior to 23.4.8844

 

Resolved Vulnerabilities

 

Path traversal vulnerability in CData API Server (CVE-2024-31848)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CData API Server version 23.4.8844

 

Referenced Sites

 

[1] CVE-2024-31848 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-31848

[2] Jetty Security Notice Overview

https://www.cdata.com/kb/entries/jetty-cve-0324.rst