CVE-2024-48914
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-48914 is a vulnerability affecting versions prior to 3.0.5 and 2.3.3 of Vendure, an open-source headless commerce platform. This issue permits an attacker to craft malicious requests that can traverse the server file system, potentially exposing sensitive data such as configuration files, environment variables, and critical server information. An additional vector for crashing the server exists via a malformed URI. Patches have been released in versions 3.0.5 and 2.3.3, and workarounds include using object storage instead of the local file system or implementing middleware to block requests containing the `/../` sequence.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Vendure