CVE-2022-46178: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
(updated )
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.
References
- github.com/advisories/GHSA-9p62-x3c5-hr5p
- github.com/metersphere/metersphere/blob/v2.5.0/framework/sdk-parent/sdk/src/main/java/io/metersphere/commons/utils/FileUtils.java
- github.com/metersphere/metersphere/releases/tag/v2.5.1
- github.com/metersphere/metersphere/security/advisories/GHSA-9p62-x3c5-hr5p
- nvd.nist.gov/vuln/detail/CVE-2022-46178
Detect and mitigate CVE-2022-46178 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →