CVE-2022-39345: Gin-vue-admin arbitrary file upload vulnerability caused by path traversal
Published Oct 25, 2022
·Updated
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue. There are no workarounds aside from upgrading to a patched version.
Affected Software
1 affected component
Gin-vue-admin Project Gin-vue-admin<2.5.4
Remediation
Patch Available
Event History
Oct 25, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for Gin-vue-admin?
The vulnerability ID for Gin-vue-admin is CVE-2022-39345.
2
What is the severity of CVE-2022-39345?
The severity of CVE-2022-39345 is critical with a CVSS score of 7.5.
3
What is the affected software version range for CVE-2022-39345?
The affected software version range for CVE-2022-39345 is up to but excluding version 2.5.4.
4
What is the CWE ID for CVE-2022-39345?
The CWE ID for CVE-2022-39345 is CWE-22 and CWE-23.
5
How do I fix CVE-2022-39345?
To fix CVE-2022-39345, you should update Gin-vue-admin to version 2.5.4 or later.