Логотип exploitDog
bind:CVE-2024-6851
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-6851

Количество 2

Количество 2

nvd логотип

CVE-2024-6851

11 месяцев назад

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mrvr-7493-pfq3

11 месяцев назад

Aim Path Traversal vulnerability

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-6851

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
github логотип
GHSA-mrvr-7493-pfq3

Aim Path Traversal vulnerability

CVSS3: 7.5
0%
Низкий
11 месяцев назад

Уязвимостей на страницу