U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-30703

Change History

CVE Translated by MITRE 5/26/2024 9:15:18 PM

Action Type Old Value New Value
Removed Translation
Title: ROS2 Galactic Geochelone
Description: Se ha descubierto una vulnerabilidad de carga de archivos arbitrarios en ROS2 (Robot Operating System 2) Galactic Geochelone ROS_VERSION 2 y ROS_PYTHON_VERSION 3, que permite a los atacantes ejecutar código arbitrario, provocar una denegación de servicio (DoS) y obtener información confidencial a través de una carga útil manipulada para el Mecanismo de carga de archivos del sistema ROS2, incluida la funcionalidad del servidor para manejar la carga de archivos y los procesos de validación asociados.

								
						

CVE Modified by MITRE 5/26/2024 9:15:18 PM

Action Type Old Value New Value
Changed Description
An arbitrary file upload vulnerability has been discovered in ROS2 (Robot Operating System 2) Galactic Geochelone ROS_VERSION 2 and ROS_PYTHON_VERSION 3, allows attackers to execute arbitrary code, cause a denial of service (DoS), and obtain sensitive information via a crafted payload to the file upload mechanism of the ROS2 system, including the server’s functionality for handling file uploads and the associated validation processes. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability.
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that there was not reasonable evidence to determine the existence of a vulnerability.
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/2

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/3

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/4

								
						
Removed Reference
MITRE http://www.openwall.com/lists/oss-security/2024/04/23/5

								
						
Removed Reference
MITRE https://github.com/yashpatelphd/CVE-2024-30703

								
						
Removed Tag
MITRE disputed

								
						

CVE Rejected by MITRE 5/26/2024 9:15:18 PM

Action Type Old Value New Value