Aller au contenu

Fiche vulnérabilité

CVE-2024-39903 : faille élevée widgetti solara (CVSS 7.5)

Description

Solara is a pure Python, React-style framework for scaling Jupyter and web apps. A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
12 juil. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • widgetti solara

Références

Rechercher une autre vulnérabilité dans la base CVE