{
  "threat_severity" : "Moderate",
  "public_date" : "2024-05-27T00:00:00Z",
  "bugzilla" : {
    "description" : "openapi-generator-online: Path traversal via outputFolder option",
    "id" : "2283564",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2283564"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-22",
  "details" : [ "OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.", "A flaw was found in OpenAPI generator, where it allows the generation of API client libraries, for example, SDK generation, server stubs, documentation, and configuration, automatically given an OpenAPI Spec. This flaw allows an attacker to cause a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory, as anyone can set the output folder when submitting the request via the `outputFolder` option." ],
  "statement" : "This vulnerability in OpenAPI Generator is classified as Moderate severity due to its potential to be exploited for unauthorized file system access, allowing attackers to perform read and delete operations on files and folders within any writable directory. The impact is mitigated by the requirement that attackers must have the ability to submit requests to the generator, limiting the exploit's feasibility to environments where access controls are already compromised or insufficiently stringent.",
  "package_state" : [ {
    "product_name" : "OpenShift Serverless",
    "fix_state" : "Not affected",
    "package_name" : "openapi-generator-online",
    "cpe" : "cpe:/a:redhat:serverless:1"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Not affected",
    "package_name" : "openapi-generator-online",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7"
  }, {
    "product_name" : "streams for Apache Kafka",
    "fix_state" : "Not affected",
    "package_name" : "openapi-generator-online",
    "cpe" : "cpe:/a:redhat:amq_streams:1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-35219\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-35219" ],
  "name" : "CVE-2024-35219",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}