GHSA-3p2q-mh7q-9pxj

Suggest an improvement
Source
https://github.com/advisories/GHSA-3p2q-mh7q-9pxj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-3p2q-mh7q-9pxj/GHSA-3p2q-mh7q-9pxj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3p2q-mh7q-9pxj
Withdrawn
2023-06-19T20:16:20Z
Published
2023-06-19T03:30:19Z
Modified
2024-11-29T05:42:40Z
Summary
Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-wm5g-p99q-66g4. This link is maintained to preserve external references.

Original Description

_joinPath in elFinderVolumeLocalFileSystem.class.php in elFinder before 2.1.62 allows path traversal in the PHP LocalVolumeDriver connector.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-06-19T20:16:20Z",
    "nvd_published_at":  "2023-06-19T01:15:08Z",
    "severity":  "HIGH"
}
References

Affected packages

Packagist / studio-42/elfinder

Package

Name
studio-42/elfinder
Purl
pkg:composer/studio-42/elfinder

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.62

Affected versions

2.*
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.1.7
2.1.8
2.1.9
2.1.10
2.1.11
2.1.12
2.1.13
2.1.14
2.1.15
2.1.16
2.1.17
2.1.18
2.1.19
2.1.20
2.1.21
2.1.22
2.1.23
2.1.24
2.1.25
2.1.26
2.1.27
2.1.28
2.1.29
2.1.30
2.1.31
2.1.32
2.1.33
2.1.34
2.1.35
2.1.36
2.1.37
2.1.38
2.1.39
2.1.40
2.1.41
2.1.42
2.1.43
2.1.44
2.1.45
2.1.46
2.1.47
2.1.48
2.1.49
2.1.50
2.1.51
2.1.52
2.1.53
2.1.54
2.1.55
2.1.56
2.1.57
2.1.58
2.1.59
2.1.60
2.1.61

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-3p2q-mh7q-9pxj/GHSA-3p2q-mh7q-9pxj.json"