CVE-2024-30254

MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1.4 allows overwriting arbitrary files if the attacker can make the victim either run the language server within a specific crafted project or `mesonlsp --full`. Version 4.1.4 contains a patch for this issue. As a workaround, avoid running `mesonlsp --full` and set the language server option `others.neverDownloadAutomatically` to `true`.
Configurations

No configuration.

History

21 Nov 2024, 09:11

Type Values Removed Values Added
Summary
  • (es) MesonLSP es un servidor de lenguaje no oficial y no respaldado para meson escrito en C++. Una vulnerabilidad en versiones anteriores a la 4.1.4 permite sobrescribir archivos arbitrarios si el atacante puede hacer que la víctima ejecute el servidor de idioma dentro de un proyecto manipulado específico o `mesonlsp --full`. La versión 4.1.4 contiene un parche para este problema. Como workaround, evite ejecutar `mesonlsp --full` y establezca la opción del servidor de idioma `others.neverDownloadAutomatically` en `true`.
References () https://github.com/JCWasmx86/mesonlsp/commit/594b6334061371911cd59389124ab8af30ce0a3a - () https://github.com/JCWasmx86/mesonlsp/commit/594b6334061371911cd59389124ab8af30ce0a3a -
References () https://github.com/JCWasmx86/mesonlsp/security/advisories/GHSA-48c5-35fh-846h - () https://github.com/JCWasmx86/mesonlsp/security/advisories/GHSA-48c5-35fh-846h -

04 Apr 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-04 19:15

Updated : 2024-11-21 09:11


NVD link : CVE-2024-30254

Mitre link : CVE-2024-30254

CVE.ORG link : CVE-2024-30254


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')