An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS03ZmoyLXJycTYtcnBocc4AAvPf
melisplatform/melis-asset-manager vulnerable to Path Traversal
Attackers can read arbitrary files on affected versions of
melisplatform/melis-asset-manager, leading to the disclosure of sensitive information. Conducting this attack does not require authentication.
Users should immediately upgrade to
melisplatform/melis-asset-manager >= 5.0.1.
This issue was addressed by restricting access to files to intended directories only.
For more information
If you have any questions or comments about this advisory, you can contact:
- The original reporters, by sending an email to vulnerability.research [at] sonarsource.com;
- The maintainers, by opening an issue on this repository.
Source: GitHub Advisory Database
Published: 12 months ago
Updated: 8 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-7fj2-rrq6-rphq, CVE-2022-39296
Fixed in: 5.0.1