Описание
Audiobookshelf is a self-hosted audiobook and podcast server. In versions 2.4.3 and prior, any user (regardless of their permissions) may be able to read files from the local file system due to a path traversal in the /hls endpoint. This issue may lead to Information Disclosure. As of time of publication, no patches are available.
Ссылки
- Product
- ExploitThird Party Advisory
- Product
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.4.3 (включая)
cpe:2.3:a:audiobookshelf:audiobookshelf:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.0012
Низкий
7.5 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-22
EPSS
Процентиль: 31%
0.0012
Низкий
7.5 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-22