Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an attacker to craft a request which is able to traverse the server file system and retrieve the contents of arbitrary files, including sensitive data such as configuration files, environment variables,...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2377070
💾 Vendure Arbitrary File Read / Denial Of Service
⏱️ vor 641d 2h (24.10.2024 um 15:42 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com