Vulnerability Description
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aimstack | Aim | 3.22.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/839703fb-23b7-4dc4-ae81-44cd4740d3f3ExploitThird Party Advisory
FAQ
What is CVE-2024-6851?
CVE-2024-6851 is a vulnerability with a CVSS score of 7.5 (HIGH). In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the mat...
How severe is CVE-2024-6851?
CVE-2024-6851 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6851?
Check the references section above for vendor advisories and patch information. Affected products include: Aimstack Aim.