CVE-2024-35219
HIGH8.3EPSS 40.1%OpenAPI Generator Online - Arbitrary File Read/Delete
Published: 5/28/2024Modified: 5/28/2024
Description
### Impact Attackers can exploit the vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. ### Patches The issue was fixed via https://github.com/OpenAPITools/openapi-generator/pull/18652 (included in v7.6.0 release) by removing the usage of the `outputFolder` option. ### Workarounds No workaround available. ### References No other reference available.
Affected packages (1)
- Maven/org.openapitools:openapi-generator-onlinefrom 0, < 7.6.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
References (5)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2024-35219
- PATCHhttps://github.com/OpenAPITools/openapi-generator
- WEBhttps://github.com/OpenAPITools/openapi-generator/commit/edbb021aadae47dcfe690313ce5119faf77f800d
- WEBhttps://github.com/OpenAPITools/openapi-generator/pull/18652
- WEBhttps://github.com/OpenAPITools/openapi-generator/security/advisories/GHSA-g3hr-p86p-593h