Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS03ZmoyLXJycTYtcnBocc4AAvPf
melisplatform/melis-asset-manager vulnerable to Path Traversal
Impact
Attackers can read arbitrary files on affected versions of melisplatform/melis-asset-manager
, leading to the disclosure of sensitive information. Conducting this attack does not require authentication.
Users should immediately upgrade to melisplatform/melis-asset-manager
>= 5.0.1.
Patches
This issue was addressed by restricting access to files to intended directories only.
References
- https://github.com/melisplatform/melis-asset-manager/commit/a0f75918c049aff78953a0bc91c585153595d1bd
For more information
If you have any questions or comments about this advisory, you can contact:
- The original reporters, by sending an email to vulnerability.research [at] sonarsource.com;
- The maintainers, by opening an issue on this repository.
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03ZmoyLXJycTYtcnBocc4AAvPf
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 12 months ago
Updated: 8 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-7fj2-rrq6-rphq, CVE-2022-39296
References:
- https://github.com/melisplatform/melis-asset-manager/security/advisories/GHSA-7fj2-rrq6-rphq
- https://nvd.nist.gov/vuln/detail/CVE-2022-39296
- https://github.com/melisplatform/melis-asset-manager/commit/a0f75918c049aff78953a0bc91c585153595d1bd
- https://github.com/advisories/GHSA-7fj2-rrq6-rphq
Affected Packages
packagist:melisplatform/melis-asset-manager
Versions: < 5.0.1Fixed in: 5.0.1