com.netflix.genie:genie-web@4.0.0-rc.67 vulnerabilities

  • latest version

    4.3.20

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    3 months ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.netflix.genie:genie-web package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Path Traversal

    Affected versions of this package are vulnerable to Path Traversal via the file upload process. An attacker can manipulate the file path and content by providing a custom filename in the multipart/form-data request, allowing the file to be written to arbitrary locations on the server where the Java process has write permissions.

    Note: Genie users who do not store these attachments locally on the underlying file system are not vulnerable to this issue.

    How to fix Path Traversal?

    Upgrade com.netflix.genie:genie-web to version 4.3.18 or higher.

    [,4.3.18)