MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations. The issue is addressed in MPXJ version 13.5.1.
History

Tue, 29 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mpxj
Mpxj mpxj
CPEs cpe:2.3:a:mpxj:mpxj:*:*:*:*:*:*:*:*
Vendors & Products Mpxj
Mpxj mpxj
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
Description MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations. The issue is addressed in MPXJ version 13.5.1.
Title MPXJ has a Potential Path Traversal Vulnerability
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-10-28T16:57:43.271Z

Updated: 2024-10-29T13:37:18.103Z

Reserved: 2024-10-18T13:43:23.458Z

Link: CVE-2024-49771

cve-icon Vulnrichment

Updated: 2024-10-29T13:37:10.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-28T17:15:04.540

Modified: 2024-10-29T14:34:50.257

Link: CVE-2024-49771

cve-icon Redhat

No data.