Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qj5-cmpw-fvpq

Опубликовано: 04 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.

EPSS

Процентиль: 43%
0.0021
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.8
nvd
больше 3 лет назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server before 2.2.3-0331 allows remote authenticated users to read arbitrary files via unspecified vectors.

EPSS

Процентиль: 43%
0.0021
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-22