We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6851

Arbitrary File Deletion in aimhubio/aim



Description

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.

Reserved 2024-07-17 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


HIGH: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Any version
affected

References

huntr.com/bounties/839703fb-23b7-4dc4-ae81-44cd4740d3f3

cve.org (CVE-2024-6851)

nvd.nist.gov (CVE-2024-6851)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-6851

Support options

Helpdesk Chat, Email, Knowledgebase