Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

Dagster vulnerable to Path Traversal attack through its /logs endpoint

GHSA-q93c-p2mw-p23f · CVE-2023-51232

Published · Modified

Description

Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.10 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').

Ready to move

Start Securing

Free, no credit card | First findings in minutes