Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8cjm-642p-wq8x

Опубликовано: 10 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts outside the intended storage location. In certain configurations this enables arbitrary file write and may be leveraged to achieve remote code execution.

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts outside the intended storage location. In certain configurations this enables arbitrary file write and may be leveraged to achieve remote code execution.

EPSS

Процентиль: 64%
0.00467
Низкий

8.8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can cause the server to create upload-related artifacts outside the intended storage location. In certain configurations this enables arbitrary file write and may be leveraged to achieve remote code execution.

EPSS

Процентиль: 64%
0.00467
Низкий

8.8 High

CVSS3

Дефекты

CWE-22