High severity7.5NVD Advisory· Published Nov 1, 2017· Updated May 13, 2026
CVE-2017-16248
CVE-2017-16248
Description
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.
Affected products
1- cpe:2.3:a:catalyst-plugin-static-simple_project:catalyst-plugin-static-simple:*:*:*:*:*:perl:*:*Range: <0.34
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- bugs.debian.org/880458nvdThird Party Advisory
- rt.cpan.org/Public/Bug/Display.htmlnvdIssue TrackingThird Party Advisory
- metacpan.org/changes/distribution/Catalyst-Plugin-Static-SimplenvdRelease Notes
News mentions
0No linked articles in our index yet.