← Back
CVE-2026-19758
high
CVSS 7.3
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
Summary
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some...
AI summary openai / gpt-4o
dromara lamp-cloud 5.10.0以下に脆弱性があり、リモートでパス・トラバーサルが可能です。FileChunkController.javaのchunk-checkエンドポイントで名前の引数を操作することで発生します。攻撃手法が公開されており、利用される可能性があります。
❓ What is the problem
dromara lamp-cloudにおけるパス・トラバーサルの脆弱性
📍 Affected scope
FileChunkController.javaのchunk-checkエンドポイント
🔥 Severity
パス・トラバーサルによりシステムファイルに不正アクセス可能なため、重要です。
🔧 How to fix
現時点で修正方法は公開されていません。プロジェクトへの問い合わせが必要です。
🛡️ Workaround
ソフトウェアのバージョンアップが公開されるまで、外部からのアクセスを制限することが推奨されます。
🔍 Detection
影響を受けるエンドポイントへの意図しないファイルアクセスを監視します。