CVE-2024-32982 is a Local File Inclusion (LFI) vulnerability affecting the static file serving component of Litestar and Starlite frameworks prior to versions 2.8.3, 2.7.2, and 2.6.4. This flaw, located in litestar/static_files/base.py, allows unauthenticated attackers to exploit path traversal to access sensitive files outside designated directories. With a CVSS score of 8.2 (HIGH), the vulnerability poses a significant risk of sensitive information disclosure and potential server compromise, requiring no user interaction or complex attack conditions. There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Litestar-Org | Litestar | >= 1.37.0, <= 1.51.14, >= 2.0.0, < 2.6.4, >= 2.7.0, < 2.7.2, >= 2.8.0, < 2.8.3CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.