CVE-2024-12866: Local File Inclusion in netease-youdao/qanything
A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12866?
CVE-2024-12866 has a high severity due to its potential for remote code execution and unauthorized file access.
How do I fix CVE-2024-12866?
To fix CVE-2024-12866, upgrade netease-youdao/qanything to the latest version that addresses the local file inclusion issue.
What systems are affected by CVE-2024-12866?
CVE-2024-12866 affects netease-youdao/qanything version v2.0.0.
What risks are associated with CVE-2024-12866?
CVE-2024-12866 can lead to the exposure of sensitive files, including private SSH keys, and enable remote code execution.
Is there a workaround for CVE-2024-12866?
Temporarily, restrict access to the application or monitor file requests until the vulnerable version is upgraded to mitigate risks associated with CVE-2024-12866.