Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36r5-jp7x-x82r

Опубликовано: 05 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

When uploading organism or sequence data via the web interface, GMOD Apollo

will unzip and inspect the files and will not check for path traversal in supported archive types.

When uploading organism or sequence data via the web interface, GMOD Apollo

will unzip and inspect the files and will not check for path traversal in supported archive types.

EPSS

Процентиль: 62%
0.00434
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-23

Связанные уязвимости

CVSS3: 9.8
nvd
11 месяцев назад

When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and will not check for path traversal in supported archive types.

EPSS

Процентиль: 62%
0.00434
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-23