Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS03ZmoyLXJycTYtcnBocc4AAvPf

melisplatform/melis-asset-manager vulnerable to Path Traversal

Impact

Attackers can read arbitrary files on affected versions of melisplatform/melis-asset-manager, leading to the disclosure of sensitive information. Conducting this attack does not require authentication.

Users should immediately upgrade to melisplatform/melis-asset-manager >= 5.0.1.

Patches

This issue was addressed by restricting access to files to intended directories only.

References

For more information

If you have any questions or comments about this advisory, you can contact:

Permalink: https://github.com/advisories/GHSA-7fj2-rrq6-rphq
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03ZmoyLXJycTYtcnBocc4AAvPf
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 12 months ago
Updated: 8 months ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-7fj2-rrq6-rphq, CVE-2022-39296
References:

Affected Packages

packagist:melisplatform/melis-asset-manager
Versions: < 5.0.1
Fixed in: 5.0.1