CVE-2024-41163
PoC nicheUnauthenticated directory traversal in Veertu Anka Build 1.42.0
Veertu Anka Build version 1.42.0 contains a directory traversal vulnerability (CWE-22) in its archive functionality. An unauthenticated, remote attacker can send a specially crafted HTTP request to the Anka Build Cloud service that traverses outside the intended directory. Successful exploitation results in disclosure of sensitive information, effectively reading files outside the intended archive path, with high confidentiality impact but no integrity or availability impact per the CVSS 7.5 score. Any organization running Veertu Anka Build 1.42.0, typically deployed as private CI/CD infrastructure for macOS/iOS builds, is affected. A public proof-of-concept is available via Cisco Talos (TALOS-2024-2059), the issue is not yet in CISA KEV, and EPSS assigns a 52.5% probability of exploitation within 30 days (99th percentile), so defenders should treat exploitation risk as elevated.
What to do: Upgrade Anka Build to a release newer than 1.42.0 following Veertu's guidance for TALOS-2024-2059 / CVE-2024-41163, as no fixed version number is specified in the available data. Until upgraded, restrict network access to the Anka Build Cloud controller API to trusted hosts, since the flaw is triggered by an unauthenticated HTTP request. Review controller logs for suspicious requests to the archive endpoint and for evidence that sensitive files were retrieved.
| veertu Anka Build Cloud (Anka Build) | 1.42.0 (version named as affected in the Talos advisory; full affected version range not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
- Vendors
- veertu
- Products
- anka build cloud
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N