Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjjg-rvc7-5p7r

Опубликовано: 19 июн. 2023
Источник: github
Github: Не прошло ревью

Описание

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

EPSS

Процентиль: 100%
0.91956
Критический

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость функции fileRead() платформы для создания баз данных в виде таблиц NocoDB, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 100%
0.91956
Критический