{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/haiyue-hcm-cloud/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:inspur:haiyue_hcm_cloud:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2024-58387"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Haiyue HCM Cloud"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","arbitrary-file-read","directory-traversal"],"_cs_type":"threat","_cs_vendors":["Inspur"],"content_html":"\u003cp\u003eInspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint. The flaw arises from insufficient validation of user-supplied path parameters, specifically the 'index' and 'ext' query parameters. Unauthenticated remote attackers can leverage this vulnerability to perform directory traversal, allowing them to read arbitrary files from the underlying filesystem. This risk includes the unauthorized disclosure of sensitive information such as /etc/passwd, application database files, and critical system configuration files. Evidence of exploitation in the wild was first reported by the Shadowserver Foundation on November 4, 2024. Given the nature of the vulnerability and the potential for credential harvesting or infrastructure discovery, immediate patching or restriction of access to the HCM cloud interface is recommended for organizations currently running affected versions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify public-facing instances of Inspur Haiyue HCM Cloud.\u003c/li\u003e\n\u003cli\u003eAttacker probes the /api/model_report/file/download endpoint to test for path traversal vulnerabilities.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting the /api/model_report/file/download path.\u003c/li\u003e\n\u003cli\u003eAttacker injects traversal sequences into the 'index' and 'ext' parameters (e.g., /api/model_report/file/download?index=/\u0026amp;ext=etc/passwd).\u003c/li\u003e\n\u003cli\u003eThe application fails to sanitize the input, resolving the path relative to the root directory.\u003c/li\u003e\n\u003cli\u003eThe server returns the contents of the requested file in the HTTP response body.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to extract sensitive credentials or system configuration data.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized access to sensitive files residing on the server. Potential consequences include the theft of system credentials (e.g., /etc/passwd), database connection strings, API keys, or configuration files that could facilitate further compromise of the internal network and HCM system data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePrioritize patching or updating Inspur Haiyue HCM Cloud to the version provided by the vendor that addresses CVE-2024-58387.\u003c/li\u003e\n\u003cli\u003eApply the Sigma rule below to detect exploitation attempts targeting the /api/model_report/file/download endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict access to the HCM Cloud administrative and report endpoints at the network edge to authorized IPs only.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP GET requests containing directory traversal sequences (e.g., ../, /etc/passwd) targeting the identified vulnerable endpoint.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T22:37:20Z","date_published":"2026-09-30T22:37:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-inspur-hcm-file-read/","summary":"An unauthenticated arbitrary file read vulnerability (CVE-2024-58387) in Inspur Haiyue HCM Cloud allows remote attackers to disclose sensitive system files via the /api/model_report/file/download endpoint.","title":"Arbitrary File Read in Inspur Haiyue HCM Cloud","url":"https://feed.craftedsignal.io/briefs/2026-09-inspur-hcm-file-read/"}],"language":"en","title":"CraftedSignal Threat Feed - Haiyue HCM Cloud","version":"https://jsonfeed.org/version/1.1"}