Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3297 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions. |
Github GHSA |
GHSA-q297-5ff8-hc92 | FitNesse Path Traversal |
Mon, 18 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fitnesse
Fitnesse fitnesse |
|
| CPEs | cpe:2.3:a:fitnesse:fitnesse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Fitnesse
Fitnesse fitnesse |
|
| Metrics |
cvssV3_1
|
Fri, 15 Nov 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-11-18T15:17:46.230Z
Reserved: 2024-11-08T02:48:16.349Z
Link: CVE-2024-42499
Updated: 2024-11-18T15:16:44.512Z
Status : Deferred
Published: 2024-11-15T06:15:04.933
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-42499
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA