{"id":"GHSA-g3hr-p86p-593h","summary":"OpenAPI Generator Online - Arbitrary File Read/Delete","details":"### Impact\nAttackers can exploit the vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option.\n\n### Patches\nThe issue was fixed via https://github.com/OpenAPITools/openapi-generator/pull/18652 (included in v7.6.0 release)  by removing the usage of the `outputFolder` option.\n\n### Workarounds\nNo workaround available.\n\n### References\nNo other reference available.","aliases":["CVE-2024-35219"],"modified":"2026-09-10T03:50:00.426665282Z","published":"2024-05-28T15:47:57Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-05-28T15:47:57Z","nvd_published_at":"2024-05-27T16:15:09Z","cwe_ids":["CWE-22"]},"references":[{"type":"WEB","url":"https://github.com/OpenAPITools/openapi-generator/security/advisories/GHSA-g3hr-p86p-593h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35219"},{"type":"WEB","url":"https://github.com/OpenAPITools/openapi-generator/pull/18652"},{"type":"WEB","url":"https://github.com/OpenAPITools/openapi-generator/commit/edbb021aadae47dcfe690313ce5119faf77f800d"},{"type":"PACKAGE","url":"https://github.com/OpenAPITools/openapi-generator"}],"affected":[{"package":{"name":"org.openapitools:openapi-generator-online","ecosystem":"Maven","purl":"pkg:maven/org.openapitools/openapi-generator-online"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.6.0"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.1.0","3.1.1","3.1.2","3.2.0","3.2.1","3.2.2","3.2.3","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","4.0.0","4.0.0-beta","4.0.0-beta2","4.0.0-beta3","4.0.1","4.0.2","4.0.3","4.1.0","4.1.1","4.1.2","4.1.3","4.2.0","4.2.1","4.2.2","4.2.3","4.3.0","4.3.1","5.0.0","5.0.0-beta","5.0.0-beta2","5.0.0-beta3","5.0.1","5.1.0","5.1.1","5.2.0","5.2.1","5.3.0","5.3.1","5.4.0","6.0.0","6.0.0-beta","6.0.1","6.1.0","6.2.0","6.2.1","6.3.0","6.4.0","6.5.0","6.6.0","7.0.0","7.0.0-beta","7.0.1","7.1.0","7.2.0","7.3.0","7.4.0","7.5.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-g3hr-p86p-593h/GHSA-g3hr-p86p-593h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"}]}