[Japanese] | |
JVNDB-2023-000073 | |
GBrowse vulnerable to unrestricted upload of files with dangerous types | |
Overview | |
GBrowse provided by Generic Model Organism Database Project is a web-based genome browser. GBrowse allows the users to upload their own data in several file formats (see "GBrowse User Uploads"). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 5.3 (Medium) [IPA Score]
CVSS V2 Severity:
Base Metrics 5.0 (Medium) [IPA Score]
| |
Affected Products | |
| |
Generic Model Organism Database Project | |
The reporter verifies that version 1.70 is vulnerable to this issue, and that version 2.56 restricts uploading non-GFF formatted files. This indicates that the file validation mechanism may have been implemented since version 2.x. | |
Impact | |
Anyone who can upload files through the product may execute arbitrary code on the server. | |
Solution | |
[Stop using the product and Switch to the successor] | |
Vendor Information | |
Generic Model Organism Database Project | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2023/07/21 |
Date First Published | 2023/07/21 |
Date Last Updated | 2024/04/12 |