Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-47624

Опубликовано: 13 дек. 2023
Источник: nvd
CVSS3: 7.5
CVSS3: 6.5
EPSS Низкий

Описание

Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the /hls endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:*
Версия до 2.4.3 (включая)

EPSS

Процентиль: 31%
0.0012
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22

EPSS

Процентиль: 31%
0.0012
Низкий

7.5 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-22