Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwmm-864r-f54x

Опубликовано: 12 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.1

Описание

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

EPSS

Процентиль: 58%
0.00364
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.1
nvd
больше 1 года назад

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.

EPSS

Процентиль: 58%
0.00364
Низкий

9.3 Critical

CVSS4

9.1 Critical

CVSS3

Дефекты

CWE-22