Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.
Metrics
Affected Vendors & Products
References
History
Mon, 04 Nov 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-19T17:37:24.404Z
Updated: 2024-11-04T18:25:47.436Z
Reserved: 2024-05-20T21:07:48.189Z
Link: CVE-2024-36117
Vulnrichment
Updated: 2024-08-02T03:30:13.011Z
NVD
Status : Awaiting Analysis
Published: 2024-06-19T18:15:11.220
Modified: 2024-11-04T19:15:06.733
Link: CVE-2024-36117
Redhat
No data.