Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m4q-2c6r-hmc3

Опубликовано: 31 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 4.3

Описание

Solon Vulnerable to Path Traversal

A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component org.noear.solon.core.handle.RenderManager. The manipulation of the argument template with the input ../org/example/HelloApp.class leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Пакеты

Наименование

org.noear:solon-view

maven
Затронутые версииВерсия исправления

<= 3.1.0

Отсутствует

EPSS

Процентиль: 51%
0.00277
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 4.3
nvd
10 месяцев назад

A vulnerability classified as problematic was found in opensolon up to 3.1.0. This vulnerability affects the function render_mav of the file /aa of the component org.noear.solon.core.handle.RenderManager. The manipulation of the argument template with the input ../org/example/HelloApp.class leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 51%
0.00277
Низкий

5.3 Medium

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-23