{"id":"CVE-2021-41242","details":"OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and write files anywhere on the target system. The attack could be used to write files anywhere in the web root folder or outside, depending on the configuration of the system and the properly configured permission of the application server user. The attack requires an OpenOlat user account, an enabled REST API and the rights on a business object to call the vulnerable REST calls. The problem is fixed in version 15.5.12 and 16.0.5. There is a workaround available. The vulnerability requires the REST module to be enabled. Disabling the REST module or limiting the REST module via some firewall or web-server access rules to be accessed only be trusted systems will mitigate the risk.","aliases":["GHSA-62hv-rfp4-hmrm"],"modified":"2026-07-09T12:19:51.108702Z","published":"2021-12-10T23:15:09.527Z","references":[{"type":"ADVISORY","url":"https://github.com/OpenOLAT/OpenOLAT/security/advisories/GHSA-62hv-rfp4-hmrm"},{"type":"REPORT","url":"https://jira.openolat.org/browse/OO-5819"},{"type":"FIX","url":"https://github.com/OpenOLAT/OpenOLAT/commit/336d5ce80681be61a0bbf4f73d2af5d1ff67e93a"},{"type":"FIX","url":"https://github.com/OpenOLAT/OpenOLAT/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openolat/openolat","events":[{"introduced":"0"},{"fixed":"2c26fc508670671e4780f3da2688164806cf443e"},{"introduced":"bf187c55eb92ed8c87728a06ba885c874da5a15d"},{"fixed":"99985c7489f5fa43e1ebfe323ebc751f0247f0d8"},{"fixed":"336d5ce80681be61a0bbf4f73d2af5d1ff67e93a"},{"fixed":"c450df7d7ffe6afde39ebca6da9136f1caa16ec4"}],"database_specific":{"cpe":"cpe:2.3:a:frentix:openolat:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"15.5.12"},{"introduced":"16.0.0"},{"fixed":"16.0.5"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["OpenOLAT_16.0.4","OpenOLAT_15.5.11","OpenOLAT_15.5.10","OpenOLAT_16.0.3","OpenOLAT_16.0.2","OpenOLAT_15.5.9","OpenOLAT_15.5.8","OpenOLAT_16.0.1","OpenOLAT_15.5.7","OpenOLAT_16.0.0","OpenOLAT_15.5.6","OpenOLAT_15.5.5","OpenOLAT_15.5.4","OpenOLAT_15.5.3","OpenOLAT_15.5.2","OpenOLAT_15.5.1","OpenOLAT_15.5.0","OpenOLAT_15.4.0","OpenOLAT_15.3.0","OpenOLAT_15.2.0","OpenOLAT_15.1.0","OpenOLAT_15.0.0","OpenOLAT_15.pre.9","OpenOLAT_15.pre.7","OpenOLAT_15.pre.6","OpenOLAT_15.pre.4","OpenOLAT_15.pre.3","OpenOLAT_15.pre.2","OpenOLAT_15.pre.1","OpenOLAT_15.pre.0.a","OpenOLAT_14.0.0","OpenOLAT_13.2.0","OpenOLAT_13.0.0","OpenOLAT_13.0.0beta9","OpenOLAT_13.0.0beta8","OpenOLAT_13.0.0beta7","OpenOLAT_13.0.0beta6","OpenOLAT_13.0.0beta5","OpenOLAT_13.0.0beta4","OpenOLAT_13.0.0beta3","OpenOLAT_13.0.0beta1","OpenOLAT_12.3.0","OpenOLAT_12.2.0","OpenOLAT_11.3.0","OpenOLAT_10.0.5","OpenOLAT_10.0.4","OpenOLAT_10.0.3","OpenOLAT_10.0.2","OpenOLAT_10.0.1","OpenOLAT_10.0.0","OpenOLAT_9.2.0","OpenOLAT_9.1.0","OpenOLAT_9.0.0","OpenOLAT_8.1.2","OpenOLAT_8.1.1","OpenOLAT_8.1","OLAT-7.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41242.json","vanir_signatures_modified":"2026-07-09T12:19:51Z","vanir_signatures":[{"digest":{"line_hashes":["16591160500666123975488325605155070110","100665183215985695254311426065527524110","71158026307726924876168560498819938360","316221648298398342083917309296201702018","11789282661309195128885001832927000708","244588074656346721043678584863227648857","328156663949702423022125207990843022133","203240347530580055087558401948260276847"],"threshold":0.9},"id":"CVE-2021-41242-02573b92","signature_type":"Line","signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"file":"src/main/java/org/olat/modules/fo/restapi/ForumWebService.java"},"deprecated":false},{"source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"file":"src/main/java/org/olat/core/util/vfs/LocalFolderImpl.java","function":"createChildLeaf"},"deprecated":false,"digest":{"function_hash":"208271659638530209688829043824549181138","length":553},"id":"CVE-2021-41242-073dc9fc","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"function":"configure","file":"src/main/java/org/olat/restapi/repository/course/CourseElementWebService.java"},"deprecated":false,"digest":{"function_hash":"248969689245966184597972483768621512304","length":782},"id":"CVE-2021-41242-30a4db1a","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"77954591868094361829508448538701202894","length":212},"id":"CVE-2021-41242-63fcce7e","signature_type":"Function","signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"function":"createChildContainer","file":"src/main/java/org/olat/core/util/vfs/LocalFolderImpl.java"}},{"signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"file":"src/main/java/org/olat/restapi/support/MultipartReader.java","function":"servlet31"},"deprecated":false,"digest":{"function_hash":"133288298552251147923001419335724175014","length":956},"id":"CVE-2021-41242-8230649e","signature_type":"Function"},{"source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"function":"attachTaskFile","file":"src/main/java/org/olat/restapi/repository/course/CourseElementWebService.java"},"deprecated":false,"digest":{"function_hash":"62804653572434751744177832892976374493","length":1557},"id":"CVE-2021-41242-b63f448f","signature_type":"Function","signature_version":"v1"},{"source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"function":"configure","file":"src/main/java/org/olat/restapi/repository/course/CourseElementWebService.java"},"deprecated":false,"digest":{"function_hash":"85991593109315339487917229920556882267","length":1295},"id":"CVE-2021-41242-e0572435","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["264133421874961225112747875464860711553","269322543030904853935112943709768760444","333561067874657751624450717061621783107","302644528610920512017149503708528648906"],"threshold":0.9},"id":"CVE-2021-41242-e4493e87","signature_type":"Line","signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"file":"src/main/java/org/olat/restapi/support/MultipartReader.java"}},{"signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"file":"src/main/java/org/olat/core/util/vfs/LocalFolderImpl.java"},"deprecated":false,"digest":{"line_hashes":["303058766670438396775907679628930023131","30737509437614079727121606858734461528","95800378517820767849615121353582527307","70889691537032853282929337328971446396","245713845584853316847134061285715232568","268980720261238562998708971305430635809","107610766915088569059712366257705708896","245180970848087277472011939118805555893","53304387952289595722762465153500671138","33941203798336485885284678615612455727","248795306554591486284289112298744892099","269057004516163536815178360160375342391","254815627639795660733347555878747736689","135523685252031762308651532361194243121","241395343000584506397773932491057356840","19948223455247295719916640851110571164","912048355205961992098000378911698254"],"threshold":0.9},"id":"CVE-2021-41242-ffa9f42e","signature_type":"Line"},{"digest":{"line_hashes":["288038531229663637572926378469704382745","172675394836573427964411533013311004679","333690839865463089694304297910153902080","75438676271512263924868544569421332768","277736929138786242846816931364907809508","278153067770297542780140204469242655378","156735229352289512306763985152592863220","36644639786435257721122148587416325097","180047166880096356146253825894479452938","320548479226719302180468673209695753475","298198222819202193409820202736093671901","278858283114182573172973723556949203329","333720826957995505357127336849763237414","60934873948992922609448099997240853920","144352258769870960795453448543890798412","108306801764122273442674360166295196978","214306697320809722380753336340615822977","322872277023573329481244167706240405818","180047166880096356146253825894479452938","320548479226719302180468673209695753475","155542458626541859250089756563246559885","89379045401991261053554852853597175577"],"threshold":0.9},"id":"CVE-2021-41242-ffc279a3","signature_type":"Line","signature_version":"v1","source":"https://github.com/openolat/openolat/commit/c450df7d7ffe6afde39ebca6da9136f1caa16ec4","target":{"file":"src/main/java/org/olat/restapi/repository/course/CourseElementWebService.java"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}