Логотип exploitDog
bind:CVE-2024-35219
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-35219

Количество 4

Количество 4

redhat логотип

CVE-2024-35219

больше 1 года назад

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

CVSS3: 8.3
EPSS: Средний
nvd логотип

CVE-2024-35219

больше 1 года назад

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

CVSS3: 8.3
EPSS: Средний
github логотип

GHSA-g3hr-p86p-593h

больше 1 года назад

OpenAPI Generator Online - Arbitrary File Read/Delete

CVSS3: 8.3
EPSS: Средний
fstec логотип

BDU:2024-05914

больше 1 года назад

Уязвимость програмного средства автоматической генериции клиентских библиотек API OpenAPI Generator, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение, изменение или удаление данных

CVSS3: 8.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-35219

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

CVSS3: 8.3
55%
Средний
больше 1 года назад
nvd логотип
CVE-2024-35219

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

CVSS3: 8.3
55%
Средний
больше 1 года назад
github логотип
GHSA-g3hr-p86p-593h

OpenAPI Generator Online - Arbitrary File Read/Delete

CVSS3: 8.3
55%
Средний
больше 1 года назад
fstec логотип
BDU:2024-05914

Уязвимость програмного средства автоматической генериции клиентских библиотек API OpenAPI Generator, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю обойти ограничения безопасности и получить доступ на чтение, изменение или удаление данных

CVSS3: 8.3
55%
Средний
больше 1 года назад

Уязвимостей на страницу