漏洞描述
OpenAPI Generator versions 7.5.0 and below are prone to an Arbitrary File Read/Delete vulnerability. Attackers can exploit this vulnerability to read and delete files and folders from an arbitrary, writable directory.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.sonarsource.comhttps://www.sonarsource.com/blog/the-power-of-taint-analysis-uncovering-critical-code-vulnerability-in-openapi-generator/↗github.comhttps://github.com/OpenAPITools/openapi-generator/commit/edbb021aadae47dcfe690313ce5119faf77f800d↗github.comhttps://github.com/OpenAPITools/openapi-generator/pull/18652↗github.comhttps://github.com/OpenAPITools/openapi-generator/security/advisories/GHSA-g3hr-p86p-593h↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2024-35219↗