CVE-2024-42499: Fitnesse
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.
Affected products
Published 2024-11-15. Last modified 2026-06-17.