Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cwgg-57xj-g77r

Опубликовано: 01 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 6.5

Описание

changedetection.io Path Traversal

Summary

When a WebDriver is used to fetch files source:file:///etc/passwd can be used to retrieve local system files, where the more traditional file:///etc/passwd gets blocked

Details

The root cause is the payload source:file:///etc/passwdpasses the regex here and also passes the check here where a traditional file:///etc/passwd would get blocked

PoC

CL-ChangeDetection.io Path Travsersal-311024-181039.pdf

Impact

It depends on where the webdriver is deployed but generally this is a high impact vulnerability

Пакеты

Наименование

changedetection.io

pip
Затронутые версииВерсия исправления

<= 0.47.4

0.47.5

EPSS

Процентиль: 97%
0.32774
Средний

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 1 года назад

changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue.

EPSS

Процентиль: 97%
0.32774
Средний

6.9 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-22