PT-2024-20766 · Treasure Data · Digdag

P-

·

Published

2024-02-13

·

Updated

2024-10-21

·

CVE-2024-25125

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Digdag versions prior to 0.10.5.1
Description The issue is a path traversal vulnerability in Treasure Data's digdag workload automation system when it is configured to store log files locally. This may lead to information disclosure.
Recommendations For versions prior to 0.10.5.1, upgrade to release version 0.10.5.1 to resolve the issue. As a temporary workaround, consider disabling local log file storage until the upgrade is applied. Restrict access to sensitive information to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-25125
GHSA-5MP4-32RR-V3X5

Affected Products

Digdag