Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q297-5ff8-hc92

Опубликовано: 15 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

FitNesse Path Traversal

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.

Пакеты

Наименование

org.fitnesse:fitnesse

maven
Затронутые версииВерсия исправления

< 20241026

20241026

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior to 20241026. If this vulnerability is exploited, an attacker may be able to know whether a file exists at a specific path, and/or obtain some part of the file contents under specific conditions.

EPSS

Процентиль: 39%
0.00172
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22