Impact
The vulnerability is a classic path traversal flaw in the zipJsonLinesData function of the Create Connection Endpoint, allowing an attacker to manipulate the filePath argument and write or read arbitrary files on the hosting system. The impact of this flaw could be serious, potentially compromising the confidentiality and integrity of data stored on the server or enabling further privilege escalation if configuration files or application binaries are involved. The flaw does not directly grant code execution, but the ability to tamper with files is a significant security risk.
Affected Systems
Any installation of dbgate version 7.3.1 or earlier that has not yet applied a fix for the zipJsonLinesData endpoint is vulnerable. The affected component resides in packages/api/src/utility/zipJsonLinesData.js of the Create Connection Endpoint and is triggered via the publicly exposed API.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but public evidence shows that the exploit code has already been released. Remote exploitation is possible because the malicious filePath can be supplied through the API endpoint, which is accessible from outside the host environment. This combination of a public exploit, the ability to affect arbitrary files, and the lack of an immediate vendor response suggests a real risk to systems running affected versions of dbgate.
OpenCVE Enrichment