CVE-2023-0669
Description
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
Summary dbcve.org
Fortra GoAnywhere MFT contains a pre-authentication deserialization vulnerability in the License Response Servlet that allows remote attackers to inject commands by submitting a malicious serialized Java object. This enables unauthenticated remote code execution without requiring valid credentials.
Mitigation
Upgrade GoAnywhere MFT to version 7.1.2 or later to apply the patch. If immediate patching is not feasible, restrict network access to the License Response Servlet via firewall or network segmentation to reduce attack surface.