Description

OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.

INFO

Published Date :

2024-05-27T16:11:22.875Z

Last Modified :

2024-08-02T03:07:46.738Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-35219 vulnerability.

Vendors Products
Openapitools
  • Openapi-generator

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact