Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-11563

Опубликовано: 25 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.6

Описание

URLs containing percent-encoded slashes (/ or \) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

РелизСтатусПримечание
devel

not-affected

8.18.0
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
plucky

ignored

end of life, was needed
questing

released

8.14.1-2ubuntu1.1
upstream

released

8.17.0~rc3-1

Показывать по

EPSS

Процентиль: 4%
0.00017
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 4.6
nvd
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

msrc
около 1 месяца назад

wcurl path traversal with percent-encoded slashes

CVSS3: 4.6
debian
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl i ...

suse-cvrf
4 месяца назад

Security update for curl

EPSS

Процентиль: 4%
0.00017
Низкий

4.6 Medium

CVSS3