CVE-2024-36117

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.
Configurations

No configuration.

History

21 Nov 2024, 09:21

Type Values Removed Values Added
References () https://github.com/dzikoysk/reposilite/releases/tag/3.5.12 - () https://github.com/dzikoysk/reposilite/releases/tag/3.5.12 -

04 Nov 2024, 19:15

Type Values Removed Values Added
References
  • () https://github.com/dzikoysk/reposilite/commit/e172ae4b539c822d0d6e04cf090713c7202a79d6 -
  • () https://github.com/dzikoysk/reposilite/security/advisories/GHSA-82j3-hf72-7x93 -

20 Jun 2024, 12:43

Type Values Removed Values Added
Summary
  • (es) Reposilite es un administrador de repositorio de código abierto, liviano y fácil de usar para artefactos basados en Maven en el ecosistema JVM. Reposilite v3.5.10 se ve afectado por una vulnerabilidad de lectura arbitraria de archivos a través del recorrido de ruta mientras sirve archivos javadoc expandidos. Reposilite ha solucionado este problema en la versión 3.5.12. No se conocen workarounds para esta vulnerabilidad. Este problema fue descubierto e informado por el laboratorio de seguridad de GitHub y también se rastrea como GHSL-2024-074.

19 Jun 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-19 18:15

Updated : 2024-11-21 09:21


NVD link : CVE-2024-36117

Mitre link : CVE-2024-36117

CVE.ORG link : CVE-2024-36117


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')