Lucene search

K
cveGitHub_MCVE-2024-45401
HistorySep 05, 2024 - 6:15 p.m.

CVE-2024-45401

2024-09-0518:15:06
CWE-22
GitHub_M
web.nvd.nist.gov
25
stripe-cli
vulnerability
version 1.11.1
version 1.21.3
file overwrite
path traversal

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS

0

Percentile

11.1%

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

Affected configurations

Nvd
Vulners
Vulnrichment
Node
stripestripe-cliRange1.11.11.21.3
VendorProductVersionCPE
stripestripe-cli*cpe:2.3:a:stripe:stripe-cli:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "stripe",
    "product": "stripe-cli",
    "versions": [
      {
        "version": ">= 1.11.1, < 1.21.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

EPSS

0

Percentile

11.1%

Related for CVE-2024-45401