Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-40422

Опубликовано: 24 июл. 2024
Источник: nvd
CVSS3: 9.1
EPSS Критический

Описание

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stitionai:devika:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.92895
Критический

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 9.1
github
больше 1 года назад

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.

EPSS

Процентиль: 100%
0.92895
Критический

9.1 Critical

CVSS3

Дефекты

CWE-22
CWE-22