Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pf68-273c-7668

Опубликовано: 19 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

EPSS

Процентиль: 20%
0.00063
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system.

EPSS

Процентиль: 20%
0.00063
Низкий

7.5 High

CVSS3

Дефекты

CWE-22