A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in DTStack Taier 1.4.0. Affected by this issue is the function FileUtils.deleteDirectory of the file ClusterController.java of the component Cluster Creation. This manipulation of the argument clusterName causes path traversal. Remote exploitation of the attack is possible. Upgrading to version 1.5.0 can resolve this issue. Patch name: ec8c59c76aceb04ab3080543ab2d9c6a4b674729. The affected component should be upgraded. | |
| Title | DTStack Taier Cluster Creation ClusterController.java FileUtils.deleteDirectory path traversal | |
| First Time appeared |
Dtstack
Dtstack taier |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:dtstack:taier:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dtstack
Dtstack taier |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-08-14T00:15:08.895Z
Updated: 2026-08-14T00:15:08.895Z
Reserved: 2026-08-13T16:44:05.203Z
Link: CVE-2026-19763
No data.
Status : Received
Published: 2026-08-14T01:18:57.253
Modified: 2026-08-14T01:18:57.253
Link: CVE-2026-19763
No data.