CyberRota Analysis
AI-GeneratedThe vulnerability in DTStack Taier 1.4.0 affects the FileUtils.deleteDirectory function within ClusterController.java, allowing for path traversal due to improper handling of the clusterName argument. This could enable remote attackers to manipulate file paths, potentially leading to unauthorized access or data exposure. Organizations using this version of the software should prioritize upgrading to version 1.5.0 to mitigate the risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded.