Skip to content

Absolute path traversal vulnerability in digdag server

Moderate
aamine published GHSA-5mp4-32rr-v3x5 Feb 14, 2024

Package

maven io.digdag:digdag-server (Maven)

Affected versions

<= 0.10.5

Patched versions

0.10.5.1

Description

Summary

Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally.

Impact

This issue may lead to Information Disclosure.

Severity

Moderate

CVE ID

CVE-2024-25125

Weaknesses

Credits