Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fj2-rrq6-rphq

Опубликовано: 11 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

melisplatform/melis-asset-manager vulnerable to Path Traversal

Impact

Attackers can read arbitrary files on affected versions of melisplatform/melis-asset-manager, leading to the disclosure of sensitive information. Conducting this attack does not require authentication.

Users should immediately upgrade to melisplatform/melis-asset-manager >= 5.0.1.

Patches

This issue was addressed by restricting access to files to intended directories only.

References

For more information

If you have any questions or comments about this advisory, you can contact:

  • The original reporters, by sending an email to vulnerability.research [at] sonarsource.com;
  • The maintainers, by opening an issue on this repository.

Пакеты

Наименование

melisplatform/melis-asset-manager

composer
Затронутые версииВерсия исправления

< 5.0.1

5.0.1

EPSS

Процентиль: 63%
0.00442
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.6
nvd
больше 3 лет назад

MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users should immediately upgrade to `melisplatform/melis-asset-manager` >= 5.0.1. This issue was addressed by restricting access to files to intended directories only.

EPSS

Процентиль: 63%
0.00442
Низкий

7.5 High

CVSS3

Дефекты

CWE-22