Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf6v-gw88-w63q

Опубликовано: 22 июл. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

EPSS

Процентиль: 97%
0.43614
Средний

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
redhat
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
nvd
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.

CVSS3: 5.5
debian
около 2 лет назад

A directory traversal problem in the URL decoder of librsvg before 2.5 ...

suse-cvrf
около 2 лет назад

Security update for librsvg

EPSS

Процентиль: 97%
0.43614
Средний

7.5 High

CVSS3

Дефекты

CWE-22