GHSA-q297-5ff8-hc92

Suggest an improvement
Source
https://github.com/advisories/GHSA-q297-5ff8-hc92
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-q297-5ff8-hc92/GHSA-q297-5ff8-hc92.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q297-5ff8-hc92
Aliases
  • CVE-2024-42499
Published
2024-11-15T06:30:33Z
Modified
2024-11-18T21:12:17.556419Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
FitNesse Path Traversal
Details

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.

References

Affected packages

Maven / org.fitnesse:fitnesse

Package

Name
org.fitnesse:fitnesse
View open source insights on deps.dev
Purl
pkg:maven/org.fitnesse/fitnesse

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20241026

Affected versions

Other

20050731
20060719
20070619
20080702
20080812
20081201
20111025
20121220
20130530
20130531
20131109
20131110
20140201
20140418
20140623
20140630
20140901
20150114
20150226
20150424
20150814
20151230
20160515
20160618
20161106
20171210
20171212
20180127
20181221
20181223
20181224
20190110
20190118
20190119
20190127
20190202
20190216
20190224
20190406
20190409
20190416
20190417
20190418
20190421
20190428
20190508
20190620
20190628
20190716
20191110
20191217
20191229
20200108
20200128
20200205
20200304
20200307
20200308
20200404
20200501
20201213
20210410
20210516
20210605
20210606
20211006
20211030
20220319
20220815
20221102
20221219
20230503
20231029
20231203
20240219
20240707
20241023