Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext=<path> to traverse the filesystem and disclose sensitive files including /etc/passwd, application database files, and system configuration files. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-11-04 . | |
| Title | Inspur HCM Cloud Arbitrary File Read via file/download Endpoint | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T20:24:25.915Z
Reserved: 2026-09-30T20:23:27.785Z
Link: CVE-2024-58387
No data.
Status : Received
Published: 2026-09-30T21:16:52.510
Modified: 2026-09-30T21:16:52.510
Link: CVE-2024-58387
No data.
OpenCVE Enrichment
Updated: 2026-09-30T22:00:16Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')