CVE-2024-50334 - CVE House
Back to Database
Status published High CVE-2024-50334

Semicolon Path Injection on API /api;/config

Vulnerability Description

Scoold is a Q&A and a knowledge sharing platform for teams. A semicolon path injection vulnerability was found on the /api;/config endpoint. By appending a semicolon in the URL, attackers can bypass authentication and gain unauthorised access to sensitive configuration data. Furthermore, PUT requests on the /api;/config endpoint while setting the Content-Type: application/hocon header allow unauthenticated attackers to file reading via HOCON file inclusion. This allows attackers to retrieve sensitive information such as configuration files from the server, which can be leveraged for further exploitation. The vulnerability has been fixed in Scoold 1.64.0. A workaround would be to disable the Scoold API with scoold.api_enabled = false.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-50334

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

scoold
Vulnerable Versions:
< 1.64.0

Timeline

Official Publish: October 29th, 2024
Last Modified: October 29th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)