{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "19.0.0"
              },
              {
                "last_affected": "19.2.0"
              },
              {
                "introduced": "20.0.0"
              },
              {
                "fixed": "20.0.1"
              },
              {
                "introduced": "20.1.0"
              },
              {
                "fixed": "20.1.1"
              }
            ],
            "source": "AFFECTED_FIELD"
          },
          "events": [
            {
              "introduced": "dc176a9cc0f9c1da83d20d7f08bfd75a695f2c65"
            },
            {
              "last_affected": "0619c8c6eede67d61c7c8814353785d9f0b738e6"
            },
            {
              "introduced": "98e39a3a35c9d58d0102e35a870ee12c5438cdfc"
            },
            {
              "fixed": "484bf358ae9a52bf2c34056cc4027815de0b44c7"
            },
            {
              "introduced": "7e3c9be4a76c240b8df16883244513c7284bc0ee"
            },
            {
              "fixed": "217f9a9f49eb5f555b095c73c492661395ee4b0e"
            }
          ],
          "repo": "https://github.com/eclipse-sw360/sw360",
          "type": "GIT"
        }
      ]
    }
  ],
  "database_specific": {
    "cna_assigner": "eclipse",
    "cwe_ids": [
      "CWE-22",
      "CWE-73"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79653.json"
  },
  "details": "In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage with config key enable.attachment.store.to.file.system, the attacker can manipulate the filename upon upload and can essentially cause arbitrary file path traversal.\n\n\n\n\nThe immediate workaround is to disable enable.attachment.store.to.file.system or update to fixed versions.",
  "id": "CVE-2026-79653",
  "modified": "2026-08-29T03:30:35.839579651Z",
  "published": "2026-08-27T13:25:03.811Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/765"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79653.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-79653"
    },
    {
      "type": "FIX",
      "url": "https://github.com/eclipse-sw360/sw360/pull/4516"
    },
    {
      "type": "FIX",
      "url": "https://github.com/eclipse-sw360/sw360/pull/4517"
    },
    {
      "type": "FIX",
      "url": "https://github.com/eclipse-sw360/sw360/pull/4518"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ]
}