CVE-2024-36116: Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)
(updated )
Reposilite v3.5.10 is affected by an Arbitrary File Upload vulnerability via path traversal in expanding of Javadoc archives.
References
- github.com/advisories/GHSA-frvj-cfq4-3228
- github.com/dzikoysk/reposilite
- github.com/dzikoysk/reposilite/commit/848173738e4375482c70365db5cebae29f125eaa
- github.com/dzikoysk/reposilite/releases/tag/3.5.12
- github.com/dzikoysk/reposilite/security/advisories/GHSA-frvj-cfq4-3228
- nvd.nist.gov/vuln/detail/CVE-2024-36116
Detect and mitigate CVE-2024-36116 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →