PT-2026-82554 · Eclipse Foundation · Eclipse Sw360
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse SW360 versions 19.0.0 through 20.1.0
Description
When the system is configured to use file system storage via the
enable.attachment.store.to.file.system config key, an attacker can manipulate the filename during upload. This allows for arbitrary file path traversal, a technique used to access files and directories that are stored outside the intended folder.Recommendations
Update to a fixed version.
Disable the
enable.attachment.store.to.file.system configuration key as a temporary workaround.Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Sw360