Path Traversal Vulnerability in Stangirard Quivr Product
CVE-2024-6583
4.3MEDIUM
Summary
A path traversal vulnerability has been identified in the latest version of Stangirard Quivr, allowing attackers to exploit the file upload functionality. By manipulating the file path in the upload request, an attacker can upload files to arbitrary locations within an S3 bucket. This poses a significant threat as it may lead to unauthorized access or exposure of sensitive files. Proper sanitization and validation of file paths are essential to mitigate this risk.
Affected Version(s)
stangirard/quivr <= unspecified
References
CVSS V3.0
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved