Vulnerability Description
The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable to the bypass, the application must use toolkit version <=1.1.1, use ZipSecurity as a guard against path traversal, and have an exploit path. Although the control still protects attackers from escaping the application path into higher level directories (e.g., /etc/), it will allow "escaping" into sibling paths. For example, if your running path is /my/app/path you an attacker could navigate into /my/app/path-something-else. This vulnerability is patched in 1.1.2.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pixee | Java Code Security Toolkit | < 1.1.2 |
Related Weaknesses (CWE)
References
- https://github.com/pixee/java-security-toolkit/blob/7c8e93e6fb2420fb6003c54a741eProduct
- https://github.com/pixee/java-security-toolkit/commit/b885b03c9cfae53d62d239037fPatch
- https://github.com/pixee/java-security-toolkit/security/advisories/GHSA-qh4g-4m4ExploitVendor Advisory
- https://github.com/pixee/java-security-toolkit/blob/7c8e93e6fb2420fb6003c54a741eProduct
- https://github.com/pixee/java-security-toolkit/commit/b885b03c9cfae53d62d239037fPatch
- https://github.com/pixee/java-security-toolkit/security/advisories/GHSA-qh4g-4m4ExploitVendor Advisory
FAQ
What is CVE-2024-24569?
CVE-2024-24569 is a vulnerability with a CVSS score of 5.4 (MEDIUM). The Pixee Java Code Security Toolkit is a set of security APIs meant to help secure Java code. `ZipSecurity#isBelowCurrentDirectory` is vulnerable to a partial-path traversal bypass. To be vulnerable ...
How severe is CVE-2024-24569?
CVE-2024-24569 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-24569?
Check the references section above for vendor advisories and patch information. Affected products include: Pixee Java Code Security Toolkit.