Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-6851

In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.0%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2024-6851
  • Aimstack » Aim » Version: 3.22.0
    cpe:2.3:a:aimstack:aim:3.22.0


Contact Us

Shodan ® - All rights reserved