Описание
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
Ссылки
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Release NotesVendor Advisory
- PatchThird Party Advisory
- ExploitPatchThird Party Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.2.0 (исключая)
Одновременно
cpe:2.3:a:labstack:echo:*:*:*:*:*:go:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00399
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 3 лет назад
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
CVSS3: 5.3
debian
около 3 лет назад
Due to improper sanitization of user input on Windows, the static file ...
EPSS
Процентиль: 60%
0.00399
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-22