CVE-2024-39903

Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:widgetti:solara:*:*:*:*:*:*:*:*

History

05 Mar 2025, 14:53

Type Values Removed Values Added
First Time Widgetti
Widgetti solara
References () https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54 - () https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54 - Patch
References () https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w - () https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w - Vendor Advisory
CPE cpe:2.3:a:widgetti:solara:*:*:*:*:*:*:*:*

21 Nov 2024, 09:28

Type Values Removed Values Added
References () https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54 - () https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54 -
References () https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w - () https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w -
Summary
  • (es) Solara es un framework puro de Python, estilo React, para escalar Jupyter y aplicaciones web. Se identificó una vulnerabilidad de inclusión de archivos locales (LFI) en widgetti/solara, en la versión &lt;1.35.1, que se solucionó en la versión 1.35.1. Esta vulnerabilidad surge de la falla de la aplicación al validar correctamente los fragmentos de URI para secuencias directory traversal como '../' al servir archivos estáticos. Un atacante puede aprovechar esta falla manipulando la parte del fragmento del URI para leer archivos arbitrarios en el sistema de archivos local.

12 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-12 15:15

Updated : 2025-04-10 20:31


NVD link : CVE-2024-39903

Mitre link : CVE-2024-39903

CVE.ORG link : CVE-2024-39903


JSON object : View

Products Affected

widgetti

  • solara
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')