External Control of File Name or Path in Luigi - CVE-2024-21542

 

External Control of File Name or Path in Luigi - CVE-2024-21542

Published: March 21, 2025


Vulnerability identifier: #VU105947
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21542
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to overwrite arbitrary files on the system.

The vulnerability exists due to improper validation of file names when unpacking them from an archive in the _extract_packages_archive() function. A remote attacker can pass a specially crafted archive to the application and overwrite arbitrary files on the system (a.k.a. Zip Slip vulnerability).


Affected software

Luigi
APEX Cloud Platform for Red Hat OpenShift

How to mitigate CVE-2024-21542

Install updates from vendor's website.

Luigi - update to 3.6.0
APEX Cloud Platform for Red Hat OpenShift - update to 03.01.02.00

External References

Related Security Bulletins