changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Changedetection
Changedetection changedetection |
|
CPEs | cpe:2.3:a:changedetection:changedetection:-:*:*:*:*:*:*:* | |
Vendors & Products |
Changedetection
Changedetection changedetection |
|
Metrics |
ssvc
|
Fri, 01 Nov 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue. | |
Title | changedetection.io Path Traversal vulnerability | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-01T16:19:49.670Z
Updated: 2024-11-01T17:30:47.107Z
Reserved: 2024-10-28T14:20:59.335Z
Link: CVE-2024-51483
Vulnrichment
Updated: 2024-11-01T17:30:42.957Z
NVD
Status : Awaiting Analysis
Published: 2024-11-01T17:15:18.750
Modified: 2024-11-01T20:24:53.730
Link: CVE-2024-51483
Redhat
No data.