Impact
In Eclipse SW360 releases 19.0.0 through 20.1.0, permitting file system storage for attachments via the enable.attachment.store.to.file.system setting allows an attacker to craft a file name that includes directory traversal sequences. When such a file is uploaded, the service writes the data to a path derived from the supplied name, potentially outside the intended storage directory. This flaw falls under CWE‑22 and CWE‑73 and enables arbitrary file read or overwrite on the host system, which could lead to disclosure of sensitive data or execution of malicious code.
Affected Systems
Eclipse Foundation's Eclipse SW360 product. Versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, and 20.1.0 are affected when the system is configured to use file system attachment storage.
Risk and Exploitability
The CVSS score of 6.0 indicates medium severity. The absence of an EPSS score is only a data gap; the potential exploitation risk is inferred from the fact that the flaw is actionable when the setting is enabled. It is also inferred that an attacker must have the ability to upload attachments, which typically requires network access and authenticated permissions or a privileged upload role. No KEV listing indicates no widely known exploitation yet. Consequently, administrators should treat the vulnerability as a moderate to high risk until a patch is applied or the problematic configuration is disabled.
OpenCVE Enrichment