PT-2024-36571 · Siyuan · Siyuan

Elleuch-X1

·

Published

2024-12-11

·

Updated

2024-12-18

·

CVE-2024-55657

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SiYuan versions prior to 3.1.16
Description An arbitrary file read issue exists due to the absence of proper validation on the path parameter in the "/api/template/render" endpoint. This allows attackers to access sensitive files on the host system.
Recommendations For versions prior to 3.1.16, update to version 3.1.16 to resolve the issue. As a temporary workaround, consider restricting access to the "/api/template/render" endpoint until the update is applied. Avoid using the path parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-55657
GHSA-XX68-37V4-4596
GO-2024-3327
OPENSUSE-SU-2024:14599-1

Affected Products

Siyuan