PT-2024-19585 · Unknown · Liveconfig

Raphael Kuhn

·

Published

2024-02-02

·

Updated

2024-02-13

·

CVE-2024-22851

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LiveConfig versions prior to 2.5.2
Description A Directory Traversal issue allows a remote attacker to obtain sensitive information via a crafted request to the "/static/" endpoint. This enables the attacker to access files or directories that are outside the intended directory, potentially leading to information disclosure.
Recommendations For versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/static/" endpoint until a patch is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-22851

Affected Products

Liveconfig