Directory Traversal vulnerability in Speedy11CZ MCRPX v.1.4.0 and before allows a local attacker to execute arbitrary code via a crafted file.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24043.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24043.json"
"2026-07-22T02:51:05Z"
[
{
"target": {
"file": "common/src/main/java/cz/speedy11/mcrpx/common/util/ZipUtil.java",
"function": "extractMinecraft"
},
"deprecated": false,
"digest": {
"function_hash": "118215111685278071671602230717341604626",
"length": 972.0
},
"id": "CVE-2024-24043-a7cee4d6",
"source": "https://github.com/speedy11cz/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e",
"signature_version": "v1",
"signature_type": "Function"
},
{
"target": {
"file": "common/src/main/java/cz/speedy11/mcrpx/common/util/ZipUtil.java",
"function": "extractZip"
},
"deprecated": false,
"digest": {
"function_hash": "275231821311305659207831122986026375419",
"length": 1028.0
},
"id": "CVE-2024-24043-b03954b3",
"source": "https://github.com/speedy11cz/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e",
"signature_version": "v1",
"signature_type": "Function"
},
{
"target": {
"file": "common/src/main/java/cz/speedy11/mcrpx/common/util/ZipUtil.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"56932408313014443650387688952929678220",
"60001982549816268247656229615257098345",
"113389323821436570736798779328269422851",
"252595848725142804002111805393373383989",
"197403871229717698560725342956622517733",
"102357048115856912678204455879764324725",
"224343333416842060342749285221695846736",
"267670675517025857858941608672995898707"
]
},
"id": "CVE-2024-24043-de5e2243",
"source": "https://github.com/speedy11cz/mcrpx/commit/02ca6d1fd851567560046766ac9d04d20db35b8e",
"signature_version": "v1",
"signature_type": "Line"
}
]