CVE-2024-45401 HIGH

CVE-2024-45401: stripe-cli Path Traversal vulnerability

Vendor Stripe
Product stripe-cli
Weakness CWE-22 · Path traversal
Published September 5, 2024
Last update December 19, 2024

CVSS base score

7.6/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a manifest with a malformed plugin shortname installed using the --archive-url or --archive-path flags can overwrite arbitrary files. The update in version 1.21.3 addresses the path traversal vulnerability by removing the ability to install plugins from an archive URL or path. There has been no evidence of exploitation of this vulnerability.

Key dates

02Disclosure timeline

September 5, 2024 CVE published
December 19, 2024 Record updated