Cloudreve WOPI PUT_RELATIVE Path Traversal Vulnerability Alert
An early warning has been issued regarding a potential path traversal vulnerability in Cloudreve's WOPI PUT_RELATIVE handler, which could allow arbitrary file creation in the owner's account.
What happened
Cloudreve, a self-hosted file-sharing and management service, is reportedly affected by a path traversal vulnerability in its WOPI PUT_RELATIVE handler. This vulnerability appears to allow an attacker to create arbitrary files within the owner's account by improperly joining path segments. The issue is under investigation and has been tracked under the ID GHSA-49H3-CWHJ-4737. It is recommended that users upgrade to a version of Cloudreve that patches this vulnerability and review access controls for WOPI handlers to mitigate potential risks. For more detailed information, consult the primary source at https://github.com/cloudreve/cloudreve/security/advisories/GHSA-49h3-cwhj-4737.
How 0Day mitigates this
cloudreve is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.