Update

Alist

Alist

to version 3.40.0

View all applications
Patching for Windows Mac Linux

CVE Vulnerabilities for Alist

CVEPublishedSeverityDetailsExploitabilityImpact Vector
CVE‑2024‑470672024‑09‑30 16:15:09MEDIUM (6)AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoint /i/:link_name takes in a user-provided value and reflects it back in the response. The endpoint returns an application/xml response, opening it up to HTML tags via XHTML and thus leading to a XSS vulnerability. This vulnerability is fixed in 3.29.0.33NETWORK
CVE‑2023‑334982023‑06‑07 14:15:10HIGH (9)alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.36NETWORK
CVE‑2023‑317262023‑05‑23 22:15:10HIGH (8)AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.44NETWORK
CVE‑2022‑459702022‑12‑12 14:15:11MEDIUM (5)Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.23NETWORK
CVE‑2022‑459692022‑12‑15 23:15:10CRITICAL (10)Alist v3.4.0 is vulnerable to Directory Traversal,46NETWORK
CVE‑2022‑459682022‑12‑12 14:15:11HIGH (9)Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).36NETWORK
CVE‑2022‑265332022‑03‑12 01:15:36MEDIUM (6)Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.33NETWORK

Deep Windows, Mac, and Linux OS patching

Stay out of the "Negligent MSP" label because Lavawall® covers:
  • 30-312 times as many applications as popular RMMs.
  • "optional" Windows patches, including firmware and drivers
  • Mac OS and application patches
  • Linux Kernel, OS, and package patches for more distribution types than we want to admit exist
Select the operating system you care about to find how Lavawall takes care of Operating System, driver, and application patches.
Windows Mac Linux

What applications does Lavawall® monitor?

Lavawall monitors patches for over 7,500 applications. This is a summary of the most popular applications.
Click here for the full list.
Click the applications below for the current version and known vulnerabilities.
Logos are property of their respective trademark holders and are not affiliated with ThreeShield or Lavawall. We have not audited the security of most of the listed tools.
Logos, products, trade names, and company names are all the property of their respective trademark holders.
The above listing includes products that Lavawall® monitors through public information and/or proprietary statistical analysis.
Although we do have a partner relationship with some of the listed products and companies, they do not necessarily endorse Lavawall® or have integrations with our systems.