Description
Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Published: 2024-02-14
Score: 5.3 Medium
EPSS: 7.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0522 Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Github GHSA Github GHSA GHSA-5mp4-32rr-v3x5 Absolute path traversal vulnerability in digdag server
History

Mon, 21 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Treasuredata
Treasuredata digdag
CPEs cpe:2.3:a:treasuredata:digdag:*:*:*:*:*:*:*:*
Vendors & Products Treasuredata
Treasuredata digdag

Subscriptions

Treasuredata Digdag
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-14T18:51:43.903Z

Reserved: 2024-02-05T14:14:46.380Z

Link: CVE-2024-25125

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.665Z

cve-icon NVD

Status : Modified

Published: 2024-02-14T03:15:15.153

Modified: 2024-11-21T09:00:18.497

Link: CVE-2024-25125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses