Описание
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | not-affected | 1:20.2.2+dfsg-1ubuntu2 |
| devel | released | 1:23.0.3+dfsg-1ubuntu1 |
| esm-infra-legacy/trusty | not-affected | |
| esm-infra/bionic | not-affected | 1:20.2.2+dfsg-1ubuntu2 |
| esm-infra/focal | not-affected | 1:22.2.7+dfsg-1 |
| esm-infra/xenial | not-affected | 1:18.3-dfsg-1ubuntu3.1 |
| focal | not-affected | 1:22.2.7+dfsg-1 |
| precise/esm | DNE | |
| trusty | ignored | end of standard support |
| trusty/esm | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Director ...
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
Уязвимость языка программирования Erlang, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
4.3 Medium
CVSS2
7.5 High
CVSS3