CVE-2023-43803: Path traversal in Arduino Create Agent
Impact The vulnerability affects the endpoint /v2/pkgs/tools/installed and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP POST request. Further details are available in the references.
Fixed Version 1.3.3
References The issue was reported by Nozomi Networks Labs. Further details on the issue are available at the following URL: https://www.nozominetworks.com/blog/security-flaws-affect-a-component-of-the-arduino-create-cloud-ide
Other sources
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint /v2/pkgs/tools/installed and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP POST request. This issue has been addressed in version 1.3.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the impact of CVE-2023-43803?
The vulnerability allows an attacker to delete arbitrary files or folders on the affected system.
What endpoint is affected by CVE-2023-43803?
The endpoint /v2/pkgs/tools/installed is affected by the vulnerability.
How does CVE-2023-43803 handle user input?
CVE-2023-43803 handles plugin names supplied as user input.
How can an attacker exploit CVE-2023-43803?
An attacker with the ability to perform HTTP requests to the localhost interface or bypass CORS configuration can exploit CVE-2023-43803.
What is the severity of CVE-2023-43803?
CVE-2023-43803 has a severity of medium (6.1).