VDB
Sign up
MEDIUM5.3

GHSA-5mp4-32rr-v3x5

Absolute path traversal vulnerability in digdag server

Quick fix

GHSA-5mp4-32rr-v3x5 — io.digdag:digdag-server: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.10.5.1</version> for io.digdag:digdag-server

Details

### Summary

Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally.

### Impact

This issue may lead to Information Disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.digdag:digdag-server
Introduced in: 0Fixed in: 0.10.5.1
Fix# pom.xml: bump <version>0.10.5.1</version> for io.digdag:digdag-server

References