MEDIUM5.3
GHSA-5mp4-32rr-v3x5
Absolute path traversal vulnerability in digdag server
Quick fix
GHSA-5mp4-32rr-v3x5 — io.digdag:digdag-server: upgrade to the fixed version with the command below.
# pom.xml: bump <version>0.10.5.1</version> for io.digdag:digdag-serverDetails
### Summary
Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerability if it's configured to store log files locally.
### Impact
This issue may lead to Information Disclosure.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/io.digdag:digdag-server
Introduced in:
0Fixed in: 0.10.5.1Fix
# pom.xml: bump <version>0.10.5.1</version> for io.digdag:digdag-server