CVE-2024-48914

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Oct 15, 2024
Updated: Oct 16, 2024
CWE ID 22
CWE ID 20

Summary

CVE-2024-48914 is a vulnerability affecting versions prior to 3.0.5 and 2.3.3 of Vendure, an open-source headless commerce platform. This issue permits an attacker to craft malicious requests that can traverse the server file system, potentially exposing sensitive data such as configuration files, environment variables, and critical server information. An additional vector for crashing the server exists via a malformed URI. Patches have been released in versions 3.0.5 and 2.3.3, and workarounds include using object storage instead of the local file system or implementing middleware to block requests containing the `/../` sequence.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share