CVE-2024-25125: Absolute path traversal vulnerability in digdag server
Summary
Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally.
Impact
This issue may lead to Information Disclosure.
Other sources
Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally. This issue may lead to information disclosure and has been addressed in release version 0.10.5.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/io.digdag:digdag-serverto a version that resolves this vulnerability.Fixed in 0.10.5.1 - Upgrade
Upgrade
digdag serverto a version that resolves this vulnerability.Fixed in 0.10.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25125?
CVE-2024-25125 is classified as Medium severity due to the potential for information disclosure.
How do I fix CVE-2024-25125?
To mitigate CVE-2024-25125, upgrade to version 0.10.5.1 or later of the digdag-server package.
What systems are affected by CVE-2024-25125?
CVE-2024-25125 affects versions of Treasure Data's digdag up to 0.10.5.1 that store log files locally.
What type of vulnerability is CVE-2024-25125?
CVE-2024-25125 is a path traversal vulnerability that may lead to information disclosure.
What software can be impacted by CVE-2024-25125?
The impacted software for CVE-2024-25125 includes the io.digdag:digdag-server package versions up to 0.10.5.1.