First published: Tue Oct 25 2022(Updated: )
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue. There are no workarounds aside from upgrading to a patched version.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Gin-vue-admin Project Gin-vue-admin | <2.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Gin-vue-admin is CVE-2022-39345.
The severity of CVE-2022-39345 is critical with a CVSS score of 7.5.
The affected software version range for CVE-2022-39345 is up to but excluding version 2.5.4.
The CWE ID for CVE-2022-39345 is CWE-22 and CWE-23.
To fix CVE-2022-39345, you should update Gin-vue-admin to version 2.5.4 or later.