Description
OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.
INFO
Published Date :
2024-05-27T16:11:22.875Z
Last Modified :
2024-08-02T03:07:46.738Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2024-35219 vulnerability.
| Vendors | Products |
|---|---|
| Openapitools |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-35219.