VDB
Sign up
HIGH7.5

GHSA-wfm3-gq9h-mrjm

Appwrite Directory Traversal vulnerability

Quick fix

GHSA-wfm3-gq9h-mrjm — appwrite/server-ce: upgrade to the fixed version with the command below.

composer require appwrite/server-ce:^0.12.2

Details

The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to be vulnerable, `APP_STORAGE_CERTIFICATES/.well-known/acme-challenge` must exist on disk. (This pathname is automatically created if the user chooses to install Let's Encrypt certificates via Appwrite.)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/appwrite/server-ce
Introduced in: 0.5.0Fixed in: 0.12.2
Fixcomposer require appwrite/server-ce:^0.12.2

References