CVE-2024-24756

Source
https://cve.org/CVERecord?id=CVE-2024-24756
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-24756.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-24756
Aliases
  • GHSA-5cxq-25mp-q5f2
Published
2024-02-01T22:38:20.120Z
Modified
2026-02-15T03:15:33.908975Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Crafatar path traversal vulnerability
Details

Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the lib/public/ directory can be requested from the server. Instances running behind Cloudflare (including crafatar.com) are not affected. Instances using the Docker container as shown in the README are affected, but only files within the container can be read. By default, all of the files within the container can also be found in this repository and are not confidential. This vulnerability is patched in 2.1.5.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24756.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/crafatar/crafatar

Affected ranges

Type
GIT
Repo
https://github.com/crafatar/crafatar
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0.0
v2.*
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-24756.json"