Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0522 | Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-5mp4-32rr-v3x5 | Absolute path traversal vulnerability in digdag server |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 21 Oct 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Treasuredata
Treasuredata digdag |
|
| CPEs | cpe:2.3:a:treasuredata:digdag:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Treasuredata
Treasuredata digdag |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-14T18:51:43.903Z
Reserved: 2024-02-05T14:14:46.380Z
Link: CVE-2024-25125
Updated: 2024-08-01T23:36:21.665Z
Status : Modified
Published: 2024-02-14T03:15:15.153
Modified: 2024-11-21T09:00:18.497
Link: CVE-2024-25125
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA