CVE-2024-36117: Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read

CVE-2024-36117: Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享
CVE-2024-36117: Reposilite >= 3.3.0, < 3.5.12 - Arbitrary File Read
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-36117: Reposilite >= 3.3.0, < 3.5.12 – Arbitrary File Read

漏洞描述

Reposilite is an open source, lightweight and easy-to-use repository manager for Maven based artifacts in JVM ecosystem. Reposilite v3.5.10 is affected by an Arbitrary File Read vulnerability via path traversal while serving expanded javadoc files. Reposilite has addressed this issue in version 3.5.12. There are no known workarounds for this vulnerability. This issue was discovered and reported by the GitHub Security lab and is also tracked as GHSL-2024-074.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享