Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-46902

Опубликовано: 25 июл. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 6.3
EPSS Низкий

Описание

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. During the unzip operation, the code takes file paths from the ZIP archive and writes them to a Vocera temporary directory. Unfortunately, the code does not properly check if the file paths include directory traversal payloads that would escape the intended destination.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vocera:report_server:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.8.0.135 (включая)
cpe:2.3:a:vocera:voice_server:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.8.0.135 (включая)

EPSS

Процентиль: 24%
0.00082
Низкий

7.5 High

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-22
CWE-22

Связанные уязвимости

CVSS3: 7.5
github
больше 2 лет назад

An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The Vocera Report Console contains a websocket function that allows for the restoration of the database from a ZIP archive that expects a SQL import file. During the unzip operation, the code takes file paths from the ZIP archive and writes them to a Vocera temporary directory. Unfortunately, the code does not properly check if the file paths include directory traversal payloads that would escape the intended destination.

EPSS

Процентиль: 24%
0.00082
Низкий

7.5 High

CVSS3

6.3 Medium

CVSS3

Дефекты

CWE-22
CWE-22