CVE-2024-1163

The attacker may exploit a path traversal vulnerability leading to information disclosure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mapshaper:mapshaper:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:49

Type Values Removed Values Added
References () https://github.com/mbloch/mapshaper/commit/7437d903c0a87802c3751fc529d2de7098094c72 - Patch () https://github.com/mbloch/mapshaper/commit/7437d903c0a87802c3751fc529d2de7098094c72 - Patch
References () https://huntr.com/bounties/c1cbc18b-e4ab-4332-ad13-0033f0f976f5 - Exploit, Third Party Advisory () https://huntr.com/bounties/c1cbc18b-e4ab-4332-ad13-0033f0f976f5 - Exploit, Third Party Advisory

03 Nov 2024, 19:15

Type Values Removed Values Added
Summary (en) Uncontrolled Resource Consumption in GitHub repository mbloch/mapshaper prior to 0.6.44. (en) The attacker may exploit a path traversal vulnerability leading to information disclosure.
CWE CWE-400

18 Oct 2024, 18:08

Type Values Removed Values Added
CWE CWE-22
First Time Mapshaper
Mapshaper mapshaper
References () https://github.com/mbloch/mapshaper/commit/7437d903c0a87802c3751fc529d2de7098094c72 - () https://github.com/mbloch/mapshaper/commit/7437d903c0a87802c3751fc529d2de7098094c72 - Patch
References () https://huntr.com/bounties/c1cbc18b-e4ab-4332-ad13-0033f0f976f5 - () https://huntr.com/bounties/c1cbc18b-e4ab-4332-ad13-0033f0f976f5 - Exploit, Third Party Advisory
CPE cpe:2.3:a:mapshaper:mapshaper:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.7
v2 : unknown
v3 : 7.1

29 Feb 2024, 15:15

Type Values Removed Values Added
Summary (en) Path Traversal in GitHub repository mbloch/mapshaper prior to 0.6.44. (en) Uncontrolled Resource Consumption in GitHub repository mbloch/mapshaper prior to 0.6.44.
CWE CWE-22 CWE-400
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 7.7

13 Feb 2024, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 15:15

Updated : 2024-11-21 08:49


NVD link : CVE-2024-1163

Mitre link : CVE-2024-1163

CVE.ORG link : CVE-2024-1163


JSON object : View

Products Affected

mapshaper

  • mapshaper
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')