RULE(RULE ID:338556)

Rule General Information
Release Date: 2024-11-19
Rule Name: Changedetection Path Travesal Vulnerability (CVE-2024-51483)
Severity:
CVE ID:
Rule Protection Details
Description: changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/dgtlmoon/changedetection.io/releases/tag/0.47.05