melisplatform/melis-asset-manager

melisplatform/melis-asset-manager

Releases34
Frequency3 months 1 week
Last Release
Stars1
MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder.

CVE History

CVEPublishedCVSS v3CVSS v2
8.6 HIGH

MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack does not require authentication. Users should immediately upgrade to `melisplatform/melis-asset-manager` >= 5.0.1. This issue was addressed by restricting access to files to intended directories only.