{"id":"CVE-2024-24043","details":"Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file.","modified":"2026-08-12T15:15:05.061964Z","published":"2024-03-19T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24043.json"},"references":[{"type":"WEB","url":"https://gist.github.com/apple502j/193358682885fe1a6708309ce934e4ed"},{"type":"WEB","url":"https://github.com/Speedy11CZ/mcrpx/releases/tag/v1.4.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24043.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24043"},{"type":"FIX","url":"https://github.com/Speedy11CZ/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/speedy11cz/mcrpx","events":[{"introduced":"0"},{"fixed":"02ca6d1fd851567560046766ac9d04d20db35b8e"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.4.0","v1.3.0","v1.2.0","v1.0.0"],"database_specific":{"vanir_signatures_modified":"2026-08-12T15:15:05Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/speedy11cz/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e","target":{"file":"common/src/main/java/cz/speedy11/mcrpx/common/util/ZipUtil.java","function":"extractMinecraft"},"deprecated":false,"digest":{"length":972,"function_hash":"118215111685278071671602230717341604626"},"id":"CVE-2024-24043-a7cee4d6"},{"target":{"file":"common/src/main/java/cz/speedy11/mcrpx/common/util/ZipUtil.java","function":"extractZip"},"deprecated":false,"digest":{"function_hash":"275231821311305659207831122986026375419","length":1028},"id":"CVE-2024-24043-b03954b3","signature_type":"Function","signature_version":"v1","source":"https://github.com/speedy11cz/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e"},{"target":{"file":"common/src/main/java/cz/speedy11/mcrpx/common/util/ZipUtil.java"},"deprecated":false,"digest":{"line_hashes":["56932408313014443650387688952929678220","60001982549816268247656229615257098345","113389323821436570736798779328269422851","252595848725142804002111805393373383989","197403871229717698560725342956622517733","102357048115856912678204455879764324725","224343333416842060342749285221695846736","267670675517025857858941608672995898707"],"threshold":0.9},"id":"CVE-2024-24043-de5e2243","signature_type":"Line","signature_version":"v1","source":"https://github.com/speedy11cz/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24043.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AC:L/AV:L/A:N/C:N/I:H/PR:N/S:U/UI:R"}]}