CVE-2023-51232: Dagster vulnerable to Path Traversal attack through its /logs endpoint
(updated )
Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot (’.’).
References
Code Behaviors & Features
Detect and mitigate CVE-2023-51232 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →