Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip file) to UTAU, an arbitrary file may be placed.
References
Configurations
No configuration.
History
21 Nov 2024, 09:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/en/jp/JVN71404925/ - | |
References | () https://utau2008.xrea.jp/ - |
29 Oct 2024, 15:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.3 |
28 May 2024, 12:39
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 May 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-28 03:15
Updated : 2024-11-21 09:16
NVD link : CVE-2024-32944
Mitre link : CVE-2024-32944
CVE.ORG link : CVE-2024-32944
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')