Impact
A path traversal vulnerability exists in the FileUtils.deleteDirectory method within ClusterController.java of DTStack Taier 1.4.0. By manipulating the clusterName parameter, an attacker can influence the directory that is deleted, enabling removal of arbitrary directories on the filesystem. The CVE document states that the issue is remotely exploitable, suggesting that a client interaction with the affected endpoint could trigger the traversal and subsequent deletion, potentially leading to data loss or disruption of the Taier service.
Affected Systems
The affected product is DTStack Taier, specifically version 1.4.0. The issue is mitigated in version 1.5.0, which is the recommended target for update.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and requires access to the Cluster Creation API. An exploit would delete arbitrary directories, which could compromise data integrity and availability, and may serve as a foothold for further attacks if critical system directories are removed.
OpenCVE Enrichment