CVE-2024-10833
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
9.1
CRITICAL
CVSS 3.1
EPSS 0.24%
Description
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths.
How to fix CVE-2024-10833
To remediate CVE-2024-10833, upgrade the affected package to a fixed version below.
- —upgrade to 0.6.2 or later
Is CVE-2024-10833 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.6.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |