{"id":"GHSA-pcwp-26pw-j98w","summary":"CometVisu Backend for openHAB has a path traversal vulnerability","details":"openHAB's [CometVisuServlet](https://github.com/openhab/openhab-webui/blob/1c03c60f84388b9d7da0231df2d4ebb1e17d3fcf/bundles/org.openhab.ui.cometvisu/src/main/java/org/openhab/ui/cometvisu/internal/servlet/CometVisuServlet.java#L75) is susceptible to an unauthenticated path traversal vulnerability.\n\nLocal files on the server can be requested via HTTP GET on the CometVisuServlet.\n\nThis vulnerability was discovered with the help of CodeQL's [Uncontrolled data used in path expression](https://codeql.github.com/codeql-query-help/java/java-path-injection/) query.\n\n## Impact\n\nThis issue may lead to Information Disclosure.\n","aliases":["CVE-2024-42468"],"modified":"2024-08-12T16:01:17Z","published":"2024-08-09T18:24:14Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-08-09T18:24:14Z","nvd_published_at":"2024-08-12T13:38:34Z"},"references":[{"type":"WEB","url":"https://github.com/openhab/openhab-webui/security/advisories/GHSA-pcwp-26pw-j98w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42468"},{"type":"WEB","url":"https://github.com/openhab/openhab-webui/commit/630e8525835c698cf58856aa43782d92b18087f2"},{"type":"PACKAGE","url":"https://github.com/openhab/openhab-webui"},{"type":"WEB","url":"https://github.com/openhab/openhab-webui/blob/1c03c60f84388b9d7da0231df2d4ebb1e17d3fcf/bundles/org.openhab.ui.cometvisu/src/main/java/org/openhab/ui/cometvisu/internal/servlet/CometVisuServlet.java#L75"}],"affected":[{"package":{"name":"org.openhab.ui.bundles:org.openhab.ui.cometvisu","ecosystem":"Maven","purl":"pkg:maven/org.openhab.ui.bundles/org.openhab.ui.cometvisu"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 4.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-pcwp-26pw-j98w/GHSA-pcwp-26pw-j98w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"}]}