GHSA-7fj2-rrq6-rphq

Suggest an improvement
Source
https://github.com/advisories/GHSA-7fj2-rrq6-rphq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-7fj2-rrq6-rphq/GHSA-7fj2-rrq6-rphq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7fj2-rrq6-rphq
Aliases
Published
2022-10-11T20:46:33Z
Modified
2023-11-08T04:10:18Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
melisplatform/melis-asset-manager vulnerable to Path Traversal
Details

Impact

Attackers can read arbitrary files on affected versions of melisplatform/melis-asset-manager, leading to the disclosure of sensitive information. Conducting this attack does not require authentication.

Users should immediately upgrade to melisplatform/melis-asset-manager >= 5.0.1.

Patches

This issue was addressed by restricting access to files to intended directories only.

References

For more information

If you have any questions or comments about this advisory, you can contact:

  • The original reporters, by sending an email to vulnerability.research [at] sonarsource.com;
  • The maintainers, by opening an issue on this repository.
Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-10-11T20:46:33Z",
    "nvd_published_at": "2022-10-11T18:15:00Z",
    "severity": "HIGH"
}
References

Affected packages

Packagist / melisplatform/melis-asset-manager

Package

Name
melisplatform/melis-asset-manager
Purl
pkg:composer/melisplatform/melis-asset-manager

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.0.1

Affected versions

v2.*
v2.1
v2.1.1
v2.2.0
v2.3.0
v2.4.0
v2.5.1
2.*
2.5.0
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.1.0
v3.1.1
v3.1.2
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v4.*
v4.0.0
v4.0.1
v4.1.0
v5.*
v5.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-7fj2-rrq6-rphq/GHSA-7fj2-rrq6-rphq.json"