CVE-2024-36116 is a critical path traversal vulnerability affecting Reposilite, an open-source Maven repository manager. Attackers can craft malicious Javadoc archives containing path traversal characters, allowing them to write arbitrary files outside the intended directory on the Reposilite instance. This flaw carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low complexity, and potential for complete compromise, including remote code execution or overwriting package content. While no active exploitation or public exploit code is currently reported, and community discussion is minimal, the high FAUCET Risk Score indicates significant potential impact. Reposilite version 3.5.12 addresses this vulnerability, and users are strongly advised to upgrade immediately as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.3.0, < 3.5.12CPE matchmatch criteria | cpe:2.3:a:reposilite:reposilite:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.