CVE-2024-36857: Path Traversal
Published Jun 4, 2024
·Updated
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
Affected Software
2 affected components
npm/@janhq/core<=0.1.11
Homebrew Jan=0.4.12
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
Jun 4, 2024
CVE Published
via NVD·07:20 PM
Advisory Published
via GitHub·09:32 PM
Aug 14, 2024
Data Sourced
via MITRE·07:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-36857?
CVE-2024-36857 has been assessed as having a high severity due to its arbitrary file read capability.
2
How do I fix CVE-2024-36857?
To remediate CVE-2024-36857, upgrade to version 0.4.13 or later of Jan.
3
What systems are affected by CVE-2024-36857?
CVE-2024-36857 affects Jan version 0.4.12 and @janhq/core versions up to and including 0.1.11.
4
What type of vulnerability is CVE-2024-36857?
CVE-2024-36857 is classified as an arbitrary file read vulnerability.
5
What is the impact of exploiting CVE-2024-36857?
Exploiting CVE-2024-36857 can allow an attacker to read sensitive files from the server.