Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These vulnerabilities can be exploited through various attack vectors present in multiple PHP files. This vulnerability is fixed in v600.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Fri, 10 Jan 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These vulnerabilities can be exploited through various attack vectors present in multiple PHP files. This vulnerability is fixed in v600. | |
Title | Improper Path Validation Enables Path Traversal in Multiple Components in Atheos | |
Weaknesses | CWE-22 CWE-434 CWE-94 |
|
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-10T15:23:16.919Z
Updated: 2025-01-10T16:08:16.253Z
Reserved: 2024-12-30T03:00:33.654Z
Link: CVE-2025-22152
Vulnrichment
Updated: 2025-01-10T16:08:06.476Z
NVD
Status : Received
Published: 2025-01-10T16:15:29.910
Modified: 2025-01-10T16:15:29.910
Link: CVE-2025-22152
Redhat
No data.