Описание
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
Ссылки
- Third Party Advisory
- Third Party Advisory
- https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7Patch
- Third Party Advisory
- Third Party Advisory
- https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7Patch
Уязвимые конфигурации
Конфигурация 1Версия до 4.30.0 (исключая)
cpe:2.3:a:gladysassistant:gladys_assistant:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00487
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 65%
0.00487
Низкий
6.5 Medium
CVSS3
Дефекты
CWE-22