changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Changedetection
Changedetection changedetection |
|
| CPEs | cpe:2.3:a:changedetection:changedetection:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Changedetection
Changedetection changedetection |
|
| Metrics |
ssvc
|
Fri, 01 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue. | |
| Title | changedetection.io Path Traversal vulnerability | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-01T16:19:49.670Z
Updated: 2024-11-01T17:30:47.107Z
Reserved: 2024-10-28T14:20:59.335Z
Link: CVE-2024-51483
Updated: 2024-11-01T17:30:42.957Z
Status : Awaiting Analysis
Published: 2024-11-01T17:15:18.750
Modified: 2024-11-01T20:24:53.730
Link: CVE-2024-51483
No data.