Impact
The flaw is a path traversal vulnerability in the Download method of MigrationEndpoint.java within the halo Files Backup Endpoint. By manipulating the request payload, an attacker can define a file path that the server resolves outside the intended directory, enabling the reading of any file stored on the application server. This constitutes an arbitrary file read, potentially exposing sensitive configuration, user data, or code. The vulnerability is remote and publicly exploitable, with exploitation code now available.
Affected Systems
All installations of halo-dev halo released up to and including version 2.24.2 are affected. The vulnerability resides exclusively in the Files Backup Endpoint component and does not depend on the operating system or deployment environment. No specific OS or platform restrictions are applied.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the vulnerable endpoint remotely over the network without requiring local privileges or additional steps. Although the public exploit is available, the overall risk remains moderate because the flaw only permits reading files and does not provide code execution or elevated privileges. Potential consequences include data replication or leakage, but the lack of local privilege escalation limits the impact space.
OpenCVE Enrichment