Junglewise Threat Intelligence

CVE-2024-4040: CrushFTP VFS Sandbox Escape Vulnerability

CVE-2024-4040 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2024-04-24

Technologies: CrushFTP. Vendors: CrushFTP.

Executive brief

A server-side template injection (SSTI) vulnerability in CrushFTP allows unauthenticated remote attackers to escape the Virtual File System (VFS) sandbox. This enables attackers to read arbitrary files from the host filesystem, bypass authentication for administrative access, and execute remote code.

Affected products

  • CrushFTP CrushFTP versions before 10.7.1 and 11.1.0

Timeline

  • 2024-04-24: disclosed
  • 2024-04-24: kev added: Added to CISA KEV catalog
  • 2024-04-24: patched: Fixed in versions 10.7.1 and 11.1.0

Related threats