Path Traversal Affecting github.com/icewhaletech/casaos-userservice/route/v1 package, versions <0.4.6-alpha1


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.08% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMICEWHALETECHCASAOSUSERSERVICEROUTEV1-6405969
  • published7 Mar 2024
  • disclosed6 Mar 2024
  • creditCp0204

Introduced: 6 Mar 2024

CVE-2024-24765  (opens in a new tab)
CWE-35  (opens in a new tab)

How to fix?

Upgrade github.com/IceWhaleTech/CasaOS-UserService/route/v1 to version 0.4.6-alpha1 or higher.

Overview

Affected versions of this package are vulnerable to Path Traversal due to insufficient path filtering, allowing the construction of paths to access any file on the system. This can lead to unauthorized access to sensitive files, such as the application's user database, and potentially allow an attacker to obtain system root privileges by crafting specific requests.

References

CVSS Base Scores

version 3.1