Описание
Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
Ссылки
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.12.4 (исключая)
cpe:2.3:a:aahframework:aah:*:*:*:*:*:go:*:*
EPSS
Процентиль: 83%
0.0201
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 83%
0.0201
Низкий
7.5 High
CVSS3
Дефекты
CWE-22