Description
Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9794-pc4r-438w | Local File Inclusion in Solara |
References
History
Wed, 05 Mar 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Widgetti
Widgetti solara |
|
| CPEs | cpe:2.3:a:widgetti:solara:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Widgetti
Widgetti solara |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T04:33:11.210Z
Reserved: 2024-07-02T19:37:18.600Z
Link: CVE-2024-39903
Updated: 2024-08-02T04:33:11.210Z
Status : Analyzed
Published: 2024-07-12T15:15:11.177
Modified: 2025-04-10T20:31:22.160
Link: CVE-2024-39903
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA