Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-33mj-99mg-8g73

Опубликовано: 08 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 8.3

Описание

Routinator has cache path traversal when processing the module component of rsync URIs

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

Пакеты

Наименование

routinator

rust
Затронутые версииВерсия исправления

<= 0.15.1

0.15.2

EPSS

Процентиль: 37%
0.00445
Низкий

8.3 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache.

CVSS3: 7.5
debian
2 месяца назад

Routinator does not properly check the module component of rsync URIs, ...

EPSS

Процентиль: 37%
0.00445
Низкий

8.3 High

CVSS4

Дефекты

CWE-22