Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-13435

Опубликовано: 20 нояб. 2025
Источник: nvd
CVSS3: 5.6
CVSS3: 8.1
CVSS2: 5.1
EPSS Низкий

Описание

A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/src/main/java/cn/dreampie/client/HttpClient.java of the component HttpClient Module. Such manipulation of the argument filename leads to path traversal. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dreampie:resty:*:*:*:*:*:*:*:*
Версия до 1.3.1 (включая)

EPSS

Процентиль: 58%
0.00359
Низкий

5.6 Medium

CVSS3

8.1 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.6
github
3 месяца назад

Resty has a Path Traversal vulnerability

EPSS

Процентиль: 58%
0.00359
Низкий

5.6 Medium

CVSS3

8.1 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-22