Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h52q-725p-338m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.

A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.

EPSS

Процентиль: 81%
0.01517
Низкий

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 7.5
nvd
больше 4 лет назад

A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.

EPSS

Процентиль: 81%
0.01517
Низкий

Дефекты

CWE-552