Описание
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.
EPSS
Процентиль: 99%
0.87701
Высокий
8.8 High
CVSS3
Дефекты
CWE-22
CWE-20
Связанные уязвимости
CVSS3: 8.8
github
больше 1 года назад
Weave server API vulnerable to arbitrary file leak
EPSS
Процентиль: 99%
0.87701
Высокий
8.8 High
CVSS3
Дефекты
CWE-22
CWE-20