CVE-2023-0669 Information
Feb 07, 2023
cve
Description
Fortra (formerly HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object.
Reference
https://my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtml#zerodayfeb1 https://infosec.exchange/@briankrebs/109795710941843934 https://www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/ https://attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysis
Share on: