TEN Framework Vulnerability: Critical Arbitrary File Read and Write
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- ten framework (npm)
- Affected versions
- >= 0.11.71, <= 0.11.71 or >= 0.11.70, <= 0.11.70 or >= 0.11.69, <= 0.11.69 or >= 0.11.68, <= 0.11.68 or >= 0.11.67, <= 0.11.67 or >= 0.11.66, <= 0.11.66 or >= 0.11.65, <= 0.11.65 or >= 0.11.64, <= 0.11.64 or >= 0.11.63, <= 0.11.63 or >= 0.11.62, <= 0.11.62 or >= 0.11.61, <= 0.11.61 or >= 0.11.60, <= 0.11.60 or >= 0.11.59, <= 0.11.59 or >= 0.11.58, <= 0.11.58 or >= 0.11.57, <= 0.11.57 or >= 0.11.56, <= 0.11.56 or >= 0.11.55, <= 0.11.55 or >= 0.11.54, <= 0.11.54 or >= 0.11.48, <= 0.11.48 or >= 0.11.53, <= 0.11.53 or >= 0.11.52, <= 0.11.52 or >= 0.11.51, <= 0.11.51 or >= 0.11.50, <= 0.11.50 or >= 0.11.49, <= 0.11.49 or >= 0.11.47, <= 0.11.47 or >= 0.11.46, <= 0.11.46 or >= 0.11.45, <= 0.11.45 or >= 0.11.44, <= 0.11.44 or >= 0.11.43, <= 0.11.43 or >= 0.11.42, <= 0.11.42 or >= 0.11.41, <= 0.11.41 or >= 0.11.40, <= 0.11.40 or >= 0.11.39, <= 0.11.39 or >= 0.11.38, <= 0.11.38 or >= 0.11.37, <= 0.11.37 or >= 0.11.36, <= 0.11.36 or >= 0.11.35, <= 0.11.35 or >= 0.11.34, <= 0.11.34 or >= 0.11.33, <= 0.11.33 or >= 0.11.31, <= 0.11.31 or >= 0.11.32, <= 0.11.32 or >= 0.11.30, <= 0.11.30 or >= 0.11.29, <= 0.11.29 or >= 0.11.28, <= 0.11.28 or >= 0.11.27, <= 0.11.27 or >= 0.11.26, <= 0.11.26 or >= 0.11.25, <= 0.11.25 or >= 0.11.24, <= 0.11.24 or >= 0.11.23, <= 0.11.23 or >= 0.11.22, <= 0.11.22 or >= 0.11.21, <= 0.11.21 or >= 0.11.20, <= 0.11.20 or >= 0.11.19, <= 0.11.19 or >= 0.11.18, <= 0.11.18 or >= 0.11.17, <= 0.11.17 or >= 0.11.16, <= 0.11.16 or >= 0.11.15, <= 0.11.15 or >= 0.11.14, <= 0.11.14 or >= 0.11.13, <= 0.11.13 or >= 0.11.12, <= 0.11.12 or >= 0.11.11, <= 0.11.11 or >= 0.11.10, <= 0.11.10 or >= 0.11.9, <= 0.11.9 or >= 0.11.8, <= 0.11.8 or >= 0.11.7, <= 0.11.7 or >= 0.11.6, <= 0.11.6 or >= 0.11.5, <= 0.11.5 or >= 0.11.4, <= 0.11.4 or >= 0.10.37, <= 0.10.37 or >= 0.11.3, <= 0.11.3 or >= 0.11.2, <= 0.11.2 or >= 0.11.1, <= 0.11.1 or >= 0.11.0, <= 0.11.0 or >= 0.10.36, <= 0.10.36 or >= 0.10.35, <= 0.10.35 or >= 0.10.34, <= 0.10.34 or >= 0.10.33, <= 0.10.33 or >= 0.10.32, <= 0.10.32 or >= 0.10.31, <= 0.10.31 or >= 0.10.30, <= 0.10.30 or >= 0.10.29, <= 0.10.29 or >= 0.10.28, <= 0.10.28 or >= 0.10.27, <= 0.10.27 or >= 0.10.26, <= 0.10.26 or >= 0.10.25, <= 0.10.25 or >= 0.10.24, <= 0.10.24 or >= 0.10.23, <= 0.10.23 or >= 0.10.22, <= 0.10.22 or >= 0.10.21, <= 0.10.21 or >= 0.10.20, <= 0.10.20 or >= 0.10.19, <= 0.10.19 or >= 0.10.18, <= 0.10.18 or >= 0.10.17, <= 0.10.17 or >= 0.10.16, <= 0.10.16 or >= 0.10.15, <= 0.10.15 or >= 0.10.14, <= 0.10.14 or >= 0.10.13, <= 0.10.13 or >= 0.10.12, <= 0.10.12 or >= 0.10.11, <= 0.10.11 or >= 0.10.10, <= 0.10.10 or >= 0.10.9, <= 0.10.9 or >= 0.10.8, <= 0.10.8 or >= 0.10.7, <= 0.10.7 or >= 0.10.6, <= 0.10.6 or >= 0.10.5, <= 0.10.5 or >= 0.10.4, <= 0.10.4 or >= 0.10.3, <= 0.10.3 or >= 0.10.2, <= 0.10.2 or >= 0.10.1, <= 0.10.1 or >= 0.8.0, <= 0.8.0 or >= 0.7.1, <= 0.7.1 or >= 0.7.0, <= 0.7.0 or >= 0.6.2, <= 0.6.2 or >= 0.6.1, <= 0.6.1 or >= 0.5.0, <= 0.5.0 or >= v0.4.1, <= v0.4.1 or >= v0.4.0, <= v0.4.0 or >= v0.3.0, <= v0.3.0 or >= v0.3.0-rc1, <= v0.3.0-rc1 or >= v0.2.0, <= v0.2.0 or >= v0.1.0, <= v0.1.0
- Patched version
- Not yet available
TEN Framework versions 0.11.71 and below reportedly contain critical unauthenticated arbitrary file read and write vulnerabilities.
What happened
TEN Framework versions 0.11.71 and below appear to have unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious content to system paths. This vulnerability is under investigation and has not yet been exploited in the wild.
The vulnerability allows for significant risk as it enables unauthorized access and modification of system files. It is imperative for users of TEN Framework to assess their exposure and take immediate action to mitigate potential risks.
What to do about it
- Monitor the primary sources for updates on a fixed version of TEN Framework.
- Review system paths for any unauthorized changes as a precautionary measure.
- No official fix has been published yet. Continue to monitor the sources below for updates.
How 0Day would have caught this
ten framework is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using TEN Framework version 0.11.71 or below, you are potentially affected.
What should I do right now?
Monitor the primary sources for updates on a fixed version and review your system paths for any unauthorized changes.
Is there a fixed version available?
No official fix has been published yet. Continue to monitor the sources for updates.