Lucene search

K
vulnrichmentGitHub_MVULNRICHMENT:CVE-2024-45401
HistorySep 05, 2024 - 5:09 p.m.

CVE-2024-45401 stripe-cli Path Traversal vulnerability

2024-09-0517:09:08
CWE-22
GitHub_M
github.com
4
stripe payment processor
command-line tool
version 1.11.1
version 1.21.3
manifest
malformed plugin
overwrite files
archive url
archive path
path traversal
plugin installation
exploitation evidence

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

11.1%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:stripe:stripe_cli:*:*:*:*:*:*:*:*"
    ],
    "vendor": "stripe",
    "product": "stripe_cli",
    "versions": [
      {
        "status": "affected",
        "version": "1.11.1",
        "lessThan": "1.21.3",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

CVSS3

7.5

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

7

Confidence

High

EPSS

0

Percentile

11.1%

SSVC

Exploitation

none

Automatable

no

Technical Impact

total

Related for VULNRICHMENT:CVE-2024-45401