Vulnerability record · CVE-2024-41163 · published 3 October 2024
CVE-2024-41163: Veertu Anka Build archive directory traversal information disclosure
Veertu · Anka Build Cloud
Veertu Anka Build 1.42.0 contains a path traversal flaw (CWE-22) in its archive functionality. A specially crafted HTTP request can cause the server to disclose sensitive files outside the intended archive directory. Because the request is unauthenticated, any network-reachable attacker can attempt it.
Description
A directory traversal vulnerability exists in the archive functionality of Veertu Anka Build 1.42.0. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network path traversal with high confidentiality impact and high EPSS, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Veertu Anka Build 1.42.0 contains a path traversal flaw (CWE-22) in its archive functionality. A specially crafted HTTP request can cause the server to disclose sensitive files outside the intended archive directory. Because the request is unauthenticated, any network-reachable attacker can attempt it.
Impact
An attacker gains read access to files on the host, which can expose credentials, configuration, or other sensitive data. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reached over the network via HTTP against the archive functionality; the CVSS vector (AV:N/PR:N/UI:N) and description state no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.52476, 98.9th percentile), and the Talos reference is tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade Veertu Anka Build past 1.42.0 to a fixed release; confirm the fixed version with the vendor since the record does not name one.
- Restrict network access to the Anka Build archive endpoints to trusted management networks.
- Run the service with least privilege and avoid storing secrets in files reachable by the service account.
- Monitor vendor advisories for a patch and apply it as soon as available.
Detection
- Inspect HTTP request logs for archive requests containing traversal sequences such as ../ or encoded variants.
- Alert on archive endpoint responses returning files outside expected archive paths or unusual file types.
- Baseline normal archive access patterns and flag anomalous paths or high-volume enumeration.
- Review file access logs for reads of sensitive files by the Anka Build process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-2059 | ExploitThird Party Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2059 |
Track CVE-2024-41163 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-41163), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.