PT-2024-32270 · Shirasagi · Shirasagi
Shogo Kumamaru
·
Published
2024-10-14
·
Updated
2024-10-19
·
CVE-2024-46898
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SHIRASAGI versions prior to 1.19.1
Description
The issue is related to improper processing of URLs in HTTP requests, resulting in a path traversal vulnerability. If exploited, this vulnerability may allow arbitrary files on the server to be retrieved when processing crafted HTTP requests.
Recommendations
For SHIRASAGI versions prior to 1.19.1, upgrade to version 1.19.1 or later to fix the security issue. As a temporary workaround, consider restricting access to the HTTP request handler to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shirasagi