CVE-2022-24843: Path Traversal in github.com/flipped-aurora/gin-vue-admin
Published Apr 13, 2022
·Updated
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arbitrary file read vulnerability due to a lack of parameter validation. This has been resolved in version 2.5.1. There are no known workarounds for this issue.
Affected Software
1 affected component
Gin-vue-admin Project Gin-vue-admin<2.5.1
Remediation
Patch Available
Event History
Apr 13, 2022
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24843.
2
What is the severity of CVE-2022-24843?
The severity of CVE-2022-24843 is high with a CVSS score of 7.5.
3
What is Gin-vue-admin?
Gin-vue-admin is a backstage management system based on Vue and Gin.
4
What is the impact of CVE-2022-24843?
CVE-2022-24843 allows for arbitrary file read, which can lead to unauthorized access to sensitive information.
5
How do I fix CVE-2022-24843?
To fix CVE-2022-24843, update Gin-vue-admin to version 2.5.1 or later.