An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web application installation folder, e.g., files such as the obfuscated and/or compiled Kurmi source code.
Metrics
Affected Vendors & Products
References
History
Tue, 31 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-22 | |
Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Kurmi Provisioning Suite before 7.9.0.35, 7.10.x through 7.10.0.18, and 7.11.x through 7.11.0.15. A path traversal vulnerability in the DocServlet servlet allows remote attackers to retrieve any file from the Kurmi web application installation folder, e.g., files such as the obfuscated and/or compiled Kurmi source code. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-12-27T00:00:00
Updated: 2024-12-31T18:38:06.745Z
Reserved: 2024-12-02T00:00:00
Link: CVE-2024-54453
Vulnrichment
Updated: 2024-12-31T18:37:54.873Z
NVD
Status : Awaiting Analysis
Published: 2024-12-27T20:15:23.670
Modified: 2024-12-31T19:15:47.147
Link: CVE-2024-54453
Redhat
No data.