Описание
GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker can traverse directories and download files to a specific directory. Successful exploit may cause information leakage.
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:huawei:gaussdb_200:6.5.1:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00227
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
больше 3 лет назад
GaussDB 200 with version of 6.5.1 have a path traversal vulnerability. Due to insufficient input path validation, an authenticated attacker can traverse directories and download files to a specific directory. Successful exploit may cause information leakage.
EPSS
Процентиль: 45%
0.00227
Низкий
6.5 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22