{"id":"CVE-2023-51232","aliases":[],"url":"https://o3.security/vulnerability/CVE-2023-51232","summary":"Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may…","details":"Directory Traversal vulnerability in dagster-webserver Dagster thru 1.5.11 allows remote attackers to obtain sensitive information via crafted request to the /logs endpoint. This may be restricted to certain file names that start with a dot ('.').","published":"2025-07-07T14:15:23.140","modified":"2026-06-17T06:40:36.820","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/dagster-io/dagster/pull/18462","label":"dagster-io/dagster#18462"},"references":[{"type":"WEB","url":"https://github.com/dagster-io/dagster/pull/18462"},{"type":"WEB","url":"https://github.com/dagster-io/dagster/pull/18462"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T06:40:36.820"}}