Aller au contenu principal
CRITICAL

CVE-2024-48914

CVSS v3

9.1

CRITICAL

Score EPSS

60.4 %

probabilité d’exploitation au 2026-10-05

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables, and other critical data stored on the server. In the same code path is an additional vector for crashing the server via a malformed URI. Patches are available in versions 3.0.5 and 2.3.3. Some workarounds are also available. One may use object storage rather than the local file system, e.g. MinIO or S3, or define middleware which detects and blocks requests with urls containing `/../`.

Détails techniques

Publiée le
2024-10-15

Questions fréquentes

Qu’est-ce que CVE-2024-48914 ?

Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables, and other critical data stored on the server. In the same code path is an additional vector for crashing the server via a malformed URI. Patches are available in versions 3.0.5 and 2.3.3. Some workarounds are also available. One may use object storage rather than the local file system, e.g. MinIO or S3, or define middleware which detects and blocks requests with urls containing `/../`.

CVE-2024-48914 est-elle activement exploitée ?

Aucune exploitation active de CVE-2024-48914 n’est confirmée. Son score EPSS était de 60.4 % au 2026-10-05, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2024-48914 ?

CVE-2024-48914 a un score de base CVSS v3 de 9.1 (gravité CRITICAL).

CVE-2024-48914 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 50 vérifications gratuites par mois · Clé API gratuite