packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-06-19T00:00:00

Updated: 2024-08-02T16:30:45.363Z

Reserved: 2023-06-19T00:00:00

Link: CVE-2023-35844

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-06-19T02:15:08.903

Modified: 2023-06-27T15:48:14.627

Link: CVE-2023-35844

cve-icon Redhat

No data.