A path traversal vulnerability was detected in halo-dev halo up to 2.24.2. The vulnerability affects the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. This could allow a remote attacker to perform path traversal. The exploit is now public and may be used. The CVSS score is 2, with a severity of LOW. Users of halo-dev halo up to 2.24.2 should assess the vulner [truncated]
A path traversal vulnerability was identified in Halo-Dev Halo up to 2.24.2. The vulnerability affects the Theme Installation component, specifically the ThemeUtils.unzipThemeTo function in ThemeUtils.java. The issue allows for path traversal through manipulation of the metadata.name argument. The attack may be launched remotely. The project closed the issue as 'duplicate' but did not reference any other [truncated]