PT-2024-32270 · Shirasagi · Shirasagi

Shogo Kumamaru

·

Published

2024-10-14

·

Updated

2024-10-19

·

CVE-2024-46898

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SHIRASAGI versions prior to 1.19.1
Description The issue is related to improper processing of URLs in HTTP requests, resulting in a path traversal vulnerability. If exploited, this vulnerability may allow arbitrary files on the server to be retrieved when processing crafted HTTP requests.
Recommendations For SHIRASAGI versions prior to 1.19.1, upgrade to version 1.19.1 or later to fix the security issue. As a temporary workaround, consider restricting access to the HTTP request handler to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-46898

Affected Products

Shirasagi