In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
Loading...
Loading...
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2023-03-15. NVD baseline CVSS 9.8; sources differ by 0.0.
In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
March 15, 2023
November 21, 2024
Fix landed in Stellarium/stellarium commit eba61df3b386 — awaiting tagged release
https://github.com/Stellarium/stellarium/commit/eba61df3b38605befcb43687a4c0a159dbc0c5cbFix landed in Stellarium/stellarium commit 787a894897b7 — awaiting tagged release
https://github.com/Stellarium/stellarium/commit/787a894897b7872ae96e6f5804a182210edd5c78Fix landed in Stellarium/stellarium commit 1261f74dc4aa — awaiting tagged release
https://github.com/Stellarium/stellarium/commit/1261f74dc4aa6bbd01ab514343424097f8cf46b7MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Explore the affected products and dependency analysis for CVE-2023-28371
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.