Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84cw-mxhv-qvv4

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 10

Описание

Radicale is vulnerable to directory traversal on Windows Filesystem Storage Backend component

The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.

Пакеты

Наименование

Radicale

pip
Затронутые версииВерсия исправления

< 1.1

1.1

EPSS

Процентиль: 80%
0.01377
Низкий

10 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 10
ubuntu
около 10 лет назад

The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.

CVSS3: 10
nvd
около 10 лет назад

The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.

CVSS3: 10
debian
около 10 лет назад

The filesystem storage backend in Radicale before 1.1 on Windows allow ...

EPSS

Процентиль: 80%
0.01377
Низкий

10 Critical

CVSS3

Дефекты

CWE-22