Описание
Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.
Ссылки
- PatchThird Party Advisory
- Patch
- Vendor Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Patch
- Vendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.7.33 (включая)
cpe:2.3:a:boazsegev:iodine:*:*:*:*:*:ruby:*:*
EPSS
Процентиль: 59%
0.00382
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
больше 6 лет назад
Malicious URL drafting attack against iodines static file server may allow path traversal
EPSS
Процентиль: 59%
0.00382
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22