High severity7.2CISA KEVNVD Advisory· Published Feb 6, 2023· Updated Aug 6, 2026
CVE-2023-0669
CVE-2023-0669
Description
Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
metasploit-frameworkRubyGems | <= 6.0.33 | — |
Affected products
3- cpe:2.3:a:fortra:goanywhere_managed_file_transfer:*:*:*:*:*:*:*:*Range: <7.1.2
- Range: 0
Patches
Vulnerability mechanics
References
12- github.com/rapid7/metasploit-framework/pull/17607nvdPatchWEB
- packetstormsecurity.com/files/171789/Goanywhere-Encryption-Helper-7.1.1-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- attackerkb.com/topics/mg883Nbeva/cve-2023-0669/rapid7-analysisnvdExploitThird Party AdvisoryWEB
- frycos.github.io/vulns4free/2023/02/06/goanywhere-forgotten.htmlnvdExploitThird Party AdvisoryWEB
- duo.com/decipher/fortra-patches-actively-exploited-zero-day-in-goanywhere-mftnvdBroken LinkThird Party AdvisoryWEB
- github.com/advisories/GHSA-6pm2-j2v8-h3cjghsaADVISORY
- infosec.exchange/@briankrebs/109795710941843934nvdMitigationThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-0669ghsaADVISORY
- www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerability/nvdMitigationThird Party Advisory
- my.goanywhere.com/webclient/ViewSecurityAdvisories.xhtmlnvdProductWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
- www.rapid7.com/blog/post/2023/02/03/exploitation-of-goanywhere-mft-zero-day-vulnerabilityghsaWEB
News mentions
0No linked articles in our index yet.