halo-dev halo
cpe:2.3:a:halo:halo:*:*:*:*:*:*:*, +1 more
- <= 2.24.2
A path traversal vulnerability has been identified in the Halo Files Backup Endpoint component, specifically in versions through 2.24.2. The issue arises in the Download function of MigrationEndpoint.java, where the status.filename field is not properly validated. This flaw allows remote attackers to manipulate the filename parameter, potentially leading to the unauthorized reading of sensitive files from the server.
Exploitation of this vulnerability allows for arbitrary file reading, which could be used to access sensitive information on the server.
The vulnerability can be reproduced by first creating a backup through the '/backups' interface, specifying a filename that includes directory traversal sequences to access restricted files, such as the Windows 'win.ini' or 'passwd' files. After the backup is created, the file can be downloaded using the '/backups/{name}/files/{filename}' endpoint, where the filename parameter is not validated, allowing the traversal payload to be exploited.
Users are advised to update to version 2.25.0 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.