CVE-2024-40422

The snapshot_path parameter in the /api/get-browser-snapshot endpoint in stitionai devika v1 is susceptible to a path traversal attack. An attacker can manipulate the snapshot_path parameter to traverse directories and access sensitive files on the server. This can potentially lead to unauthorized access to critical system files and compromise the confidentiality and integrity of the system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:stitionai:devika:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-24 16:15

Updated : 2024-07-25 17:42


NVD link : CVE-2024-40422

Mitre link : CVE-2024-40422

CVE.ORG link : CVE-2024-40422


JSON object : View

Products Affected

stitionai

  • devika
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')