Description
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.
Remediation
References
https://github.com/FusionAuth/fusionauth-issues/issues/1983
https://fusionauth.io/docs/v1/tech/release-notes
Related Vulnerabilities
CVE-2023-23850 Vulnerability in maven package org.jenkins-ci.plugins:synopsys-coverity
CVE-2022-31103 Vulnerability in npm package lettersanitizer
CVE-2022-29172 Vulnerability in npm package auth0-lock
CVE-2019-1003034 Vulnerability in maven package org.jenkins-ci.plugins:job-dsl
CVE-2020-8203 Vulnerability in maven package org.webjars:lodash