8.2
CVE-2024-32982
- EPSS 0.23%
- Veröffentlicht 06.05.2024 15:15:23
- Zuletzt bearbeitet 21.11.2024 09:16:09
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Litestar and Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to 2.8.3, 2.7.2, and 2.6.4, a Local File Inclusion (LFI) vulnerability has been discovered in the static file serving component of LiteStar. This vulnerability allows attackers to exploit path traversal flaws, enabling unauthorized access to sensitive files outside the designated directories. Such access can lead to the disclosure of sensitive information or potentially compromise the server. The vulnerability is located in the file path handling mechanism within the static content serving function, specifically at `litestar/static_files/base.py`. This vulnerability is fixed in versions 2.8.3, 2.7.2, and 2.6.4.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstellerstarliteproject
≫
Produkt
starlite
Default Statusunknown
Version <=
1.51.14
Version
1.37.0
Status
affected
Herstellerstarliteproject
≫
Produkt
starlite
Default Statusunknown
Version <
2.6.4
Version
2.0.0
Status
affected
Herstellerstarliteproject
≫
Produkt
starlite
Default Statusunknown
Version <
2.7.2
Version
2.7.0
Status
affected
Herstellerstarliteproject
≫
Produkt
starlite
Default Statusunknown
Version <
2.8.3
Version
2.8.0
Status
affected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.453 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.