Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vq7-xgx9-437g

Опубликовано: 11 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

EPSS

Процентиль: 51%
0.00278
Низкий

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
около 4 лет назад

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

EPSS

Процентиль: 51%
0.00278
Низкий

Дефекты

CWE-200