Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fv4g-gwpj-74gr

Опубликовано: 05 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 2.4
CVSS3: 7.5

Описание

Path traversal vulnerability in stripe-cli

Impact

A vulnerability exists in stripe-cli versions 1.11.1 and higher where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files.

The update addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path.

There has been no evidence of exploitation of this vulnerability.

Recommendation

Upgrade to stripe-cli v1.21.3.

Acknowledgements

Thank you to 0xacb and bordiez for reporting this vulnerability.

For more information

Email us at security@stripe.com

Пакеты

Наименование

github.com/stripe/stripe-cli

go
Затронутые версииВерсия исправления

>= 1.11.1, < 1.21.3

1.21.3

EPSS

Процентиль: 31%
0.00116
Низкий

2.4 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

EPSS

Процентиль: 31%
0.00116
Низкий

2.4 Low

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22