CVE-2024-46898

SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploited, arbitrary files on the server may be retrieved when processing crafted HTTP requests.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ss-proj:shirasagi:*:*:*:*:*:*:*:*

History

17 Oct 2024, 17:52

Type Values Removed Values Added
CPE cpe:2.3:a:ss-proj:shirasagi:*:*:*:*:*:*:*:*
First Time Ss-proj shirasagi
Ss-proj
CVSS v2 : unknown
v3 : 8.6
v2 : unknown
v3 : 7.5
References () https://github.com/shirasagi/shirasagi/commit/5ac4685d7e4330f949f13219069107fc5d768934 - () https://github.com/shirasagi/shirasagi/commit/5ac4685d7e4330f949f13219069107fc5d768934 - Patch
References () https://jvn.jp/en/jp/JVN58721679/ - () https://jvn.jp/en/jp/JVN58721679/ - Third Party Advisory
References () https://www.ss-proj.org/ - () https://www.ss-proj.org/ - Product

15 Oct 2024, 12:57

Type Values Removed Values Added
Summary
  • (es) Las versiones anteriores a la v1.19.1 de SHIRASAGI procesan las URL de las solicitudes HTTP de forma incorrecta, lo que genera una vulnerabilidad de path traversal. Si se explota esta vulnerabilidad, se pueden recuperar archivos arbitrarios del servidor al procesar solicitudes HTTP manipuladas.

15 Oct 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-15 07:15

Updated : 2024-10-17 17:52


NVD link : CVE-2024-46898

Mitre link : CVE-2024-46898

CVE.ORG link : CVE-2024-46898


JSON object : View

Products Affected

ss-proj

  • shirasagi
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')