Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-17567

Опубликовано: 28 сент. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

not-affected

3.8.3+dfsg-3.1
disco

not-affected

3.8.3+dfsg-3.1
eoan

not-affected

3.8.3+dfsg-3.1
esm-apps/bionic

needed

esm-apps/focal

not-affected

3.8.3+dfsg-3.1
esm-apps/jammy

not-affected

3.8.3+dfsg-3.1
esm-apps/noble

not-affected

3.8.3+dfsg-3.1
esm-apps/xenial

needed

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.

CVSS3: 7.5
debian
больше 7 лет назад

Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 all ...

CVSS3: 7.5
github
больше 7 лет назад

Jekyll allows attackers to access arbitrary files by specifying a symlink

5 Medium

CVSS2

7.5 High

CVSS3