Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0522 Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Github GHSA Github GHSA GHSA-5mp4-32rr-v3x5 Absolute path traversal vulnerability in digdag server
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 21 Oct 2024 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Treasuredata
Treasuredata digdag
CPEs cpe:2.3:a:treasuredata:digdag:*:*:*:*:*:*:*:*
Vendors & Products Treasuredata
Treasuredata digdag

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-14T18:51:43.903Z

Reserved: 2024-02-05T14:14:46.380Z

Link: CVE-2024-25125

cve-icon Vulnrichment

Updated: 2024-08-01T23:36:21.665Z

cve-icon NVD

Status : Modified

Published: 2024-02-14T03:15:15.153

Modified: 2024-11-21T09:00:18.497

Link: CVE-2024-25125

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.