Executive brief
Fortra GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in the License Response Servlet. The flaw exists due to the deserialization of untrusted, attacker-controlled objects, allowing for command injection.
Affected products
- Fortra GoAnywhere Managed File Transfer (MFT) versions up to (excluding) 7.1.2
Timeline
- 2023-02-03: other: Exploitation of zero-day vulnerability reported by Rapid7
- 2023-02-06: disclosed: Public technical analysis published
- 2023-02-10: advisory
- 2023-02-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-02-15: patched: NIST records indicate patch version 7.1.2 identified