
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability identified as CVE-2021-3846 was discovered in Firefly III, related to file upload functionality (CWE-434). The issue was identified and documented in 2021 (NVD).
The vulnerability is classified as CWE-434, which relates to Unrestricted Upload of File with Dangerous Type. The issue was specifically found in the attachment handling functionality of Firefly III, where temporary files were not being properly closed and deleted (GitHub Commit).
The vulnerability could potentially lead to resource exhaustion due to temporary files not being properly cleaned up in the system.
A fix was implemented through a code commit that ensures temporary files are properly closed and deleted after processing. The specific change added a fclose($resource) call to properly handle file resources (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."