Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r7f-4h2c-5x73

Опубликовано: 01 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

fury-adapter-swagger allows arbitrary file read from system

fury-adapter-swagger from version 0.2.0 until version 0.9.7 has a weakness that allows an attacker to read arbitrary files off of the system. This can be used to read sensitive data, or to cause a denial of service condition by attempting to read something like /dev/zero.

Proof of Concept:

--- swagger: '2.0' info: title: Read local files version: '1.0' paths: /foo: get: responses: 200: description: Some description examples: text/html: example: $ref: '/etc/passwd'

Recommendation

Upgrade to version 0.9.7 or later.

Пакеты

Наименование

fury-adapter-swagger

npm
Затронутые версииВерсия исправления

>= 0.2.0, < 0.9.7

0.9.7

7.3 High

CVSS3

Дефекты

CWE-22

7.3 High

CVSS3

Дефекты

CWE-22