Количество 2
Количество 2
CVE-2023-38337
больше 2 лет назад
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project.
CVSS3: 7.5
EPSS: Низкий
GHSA-vc79-65pr-q82v
больше 2 лет назад
rswag vulnerable to arbitrary JSON and YAML file read via directory traversal
CVSS3: 7.5
EPSS: Низкий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-38337 rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag-api can expose a file that is not the OpenAPI (or Swagger) specification file of a project. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-vc79-65pr-q82v rswag vulnerable to arbitrary JSON and YAML file read via directory traversal | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу
20