CVE-2024-55658

Source
https://cve.org/CVERecord?id=CVE-2024-55658
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55658.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-55658
Aliases
Downstream
Related
Published
2024-12-11T22:47:21.809Z
Modified
2026-07-15T01:48:57.183454702Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
SiYuan has an arbitrary file read and path traversal via /api/export/exportResources
Details

SiYuan is a personal knowledge management system. Prior to version 3.1.16, SiYuan's /api/export/exportResources endpoint is vulnerable to arbitary file read via path traversal. It is possible to manipulate the paths parameter to access and download arbitrary files from the host system by traversing the workspace directory structure. Version 3.1.16 contains a patch for the issue.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/55xxx/CVE-2024-55658.json"
}
References

Affected packages

Git / github.com/siyuan-note/siyuan

Affected ranges

Type
GIT
Repo
https://github.com/siyuan-note/siyuan
Events
Database specific
{
    "cpe": "cpe:2.3:a:b3log:siyuan:3.1.15:-:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.1.15-NA"
        },
        {
            "last_affected": "3.1.15-NA"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

3.*
3.1.15-NA
v3.*
v3.1.15

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-55658.json"