Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fortra GoAnywhere MFT auth bypass bug (CVE-2024-0204) #18743

Closed
h00die opened this issue Jan 24, 2024 · 2 comments · Fixed by #18762
Closed

Fortra GoAnywhere MFT auth bypass bug (CVE-2024-0204) #18743

h00die opened this issue Jan 24, 2024 · 2 comments · Fixed by #18762
Labels
suggestion-module New module suggestions

Comments

@h00die
Copy link
Contributor

h00die commented Jan 24, 2024

Summary

CVE from 2024, auth bypass to make a new admin. https://www.bleepingcomputer.com/news/security/exploit-released-for-fortra-goanywhere-mft-auth-bypass-bug/

Basic example

https://github.com/horizon3ai/CVE-2024-0204

(untested and unreviewed)

@h00die h00die added the suggestion-module New module suggestions label Jan 24, 2024
@h00die h00die changed the title Fortra GoAnywhere MFT auth bypass bug Fortra GoAnywhere MFT auth bypass bug (CVE-2024-0204) Jan 24, 2024
@ccondon-r7
Copy link
Contributor

@h00die there should be an RCE module up for this on Monday c/o Stephen

@sfewer-r7
Copy link
Contributor

Exploit module has been added via this pull request: #18762

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-module New module suggestions
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants