Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvx5-5856-c68p

Опубликовано: 04 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.

Application administrators can read arbitrary files from the server filesystem through path traversal.

Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris.

Application administrators can read arbitrary files from the server filesystem through path traversal.

Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.

EPSS

Процентиль: 79%
0.01208
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.4
nvd
около 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesystem through path traversal. Users are recommended to upgrade to version 2.1.8, 3.0.3 or later, which fixes the issue.

EPSS

Процентиль: 79%
0.01208
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-22