VYPR
High severity7.3NVD Advisory· Published Feb 15, 2024· Updated Jun 17, 2026

CVE-2024-25123

CVE-2024-25123

Description

MSS (Mission Support System) is an open source package designed for planning atmospheric research flights. In file: index.py, there is a method that is vulnerable to path manipulation attack. By modifying file paths, an attacker can acquire sensitive information from different resources. The filename variable is joined with other variables to form a file path in _file. However, filename is a route parameter that can capture path type values i.e. values including slashes (\). So it is possible for an attacker to manipulate the file being read by assigning a value containing ../ to filename and so the attacker may be able to gain access to other files on the host filesystem. This issue has been addressed in MSS version 8.3.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:open-mss:mission_support_system:*:*:*:*:*:*:*:*
    Range: >=5.0.0,<8.3.3
  • Open MSS/MSSllm-create2 versions
    >=8.3.3+ 1 more
    • (no CPE)range: >=8.3.3
    • (no CPE)range: >= 5.0.0, < 8.3.3

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.