Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-5821

Опубликовано: 03 июл. 2024
Источник: nvd
CVSS3: 6.2
EPSS Низкий

Описание

The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file names. When a user requests the content of a file with a misspelled name, the agent attempts to correct the command and inadvertently reveals the content of the intended file, such as /etc/passwd. This can lead to unauthorized access to sensitive information and potential server compromise.

EPSS

Процентиль: 25%
0.00088
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.2
github
больше 1 года назад

Improper Access Control in stitionai/devika

EPSS

Процентиль: 25%
0.00088
Низкий

6.2 Medium

CVSS3

Дефекты

CWE-22