← Back

CVE-2024-45401

nvd nist
Published: Sep 5, 2024Modified: Jan 2, 2025

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 1.8 / Impact: 5.2
Source: NVD

Description

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

Affected (1)

Products: Stripe: Stripe Cli
1 product
Stripe Cli
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.11.1 to 1.21.3

References (1)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.