4.3.20
11 years ago
3 months ago
Known vulnerabilities in the com.netflix.genie:genie-web package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Path Traversal via the file upload process. An attacker can manipulate the file path and content by providing a custom filename in the multipart/form-data request, allowing the file to be written to arbitrary locations on the server where the Java process has write permissions. Note: Genie users who do not store these attachments locally on the underlying file system are not vulnerable to this issue. How to fix Path Traversal? Upgrade | [,4.3.18) |