Vulnerability Description
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://fitnesse.org/FitNesseDownload
- https://github.com/unclebob/fitnesse/releases/tag/20241026
- https://jvn.jp/en/jp/JVN36791327/
FAQ
What is CVE-2024-42499?
CVE-2024-42499 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know ...
How severe is CVE-2024-42499?
CVE-2024-42499 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-42499?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.