Description
MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users should immediately upgrade to `melisplatform/melis-asset-manager` >= 5.0.1. This issue was addressed by restricting access to files to intended directories only.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7045 | MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users should immediately upgrade to `melisplatform/melis-asset-manager` >= 5.0.1. This issue was addressed by restricting access to files to intended directories only. |
Github GHSA |
GHSA-7fj2-rrq6-rphq | melisplatform/melis-asset-manager vulnerable to Path Traversal |
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T16:51:37.758Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39296
Updated: 2024-08-03T12:00:44.035Z
Status : Modified
Published: 2022-10-11T18:15:10.047
Modified: 2024-11-21T07:17:58.790
Link: CVE-2022-39296
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA