HIGH
Path Traversal In MeterSpere allows file upload to any path
Published Dec 29, 2022
8.8
HIGHCVSS 3.1
EPSS 0.72%
Description
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.
Affected products
-
Affected
- < v2.5.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Metersphere | Metersphere | unknown | Affected
|
- < 2.5.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7584 Advisory
- https://github.com/advisories/GHSA-9p62-x3c5-hr5p Advisory
- https://github.com/metersphere/metersphere/blob/v2.5.0/framework/sdk-parent/sdk/src/main/java/io/metersphere/commons/utils/FileUtils.java#L5
- https://github.com/metersphere/metersphere/releases/tag/v2.5.1
- https://github.com/metersphere/metersphere/security/advisories/GHSA-9p62-x3c5-hr5p x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-46178
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Dec 29, 2022
Updated Apr 10, 2025
Reserved Nov 28, 2022
Link CVE-2022-46178
CISA Vulnrichment
Updated Apr 10, 2025
Red Hat
No data
GitHub
Link GHSA-9P62-X3C5-HR5P