Описание
Skytable is a NoSQL database with automated snapshots and TLS. Versions prior to 0.5.1 are vulnerable to a a directory traversal attack enabling remotely connected clients to destroy and/or manipulate critical files on the host's file system. This security bug has been patched in version 0.5.1. There are no known workarounds aside from upgrading.
Ссылки
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Release NotesThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.5.1 (исключая)
cpe:2.3:a:skytable:skytable:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00735
Низкий
8.8 High
CVSS3
8.1 High
CVSS3
9.4 Critical
CVSS2
Дефекты
CWE-22
CWE-22
EPSS
Процентиль: 72%
0.00735
Низкий
8.8 High
CVSS3
8.1 High
CVSS3
9.4 Critical
CVSS2
Дефекты
CWE-22
CWE-22