High severity7.5NVD Advisory· Published Nov 1, 2017· Updated Jun 17, 2026
CVE-2017-16248
CVE-2017-16248
Description
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- cpe:2.3:a:catalyst-plugin-static-simple_project:catalyst-plugin-static-simple:*:*:*:*:*:perl:*:*Range: <0.34
Patches
Vulnerability mechanics
References
3- bugs.debian.org/880458nvdThird Party Advisory
- rt.cpan.org/Public/Bug/Display.htmlnvdIssue TrackingThird Party Advisory
- metacpan.org/changes/distribution/Catalyst-Plugin-Static-SimplenvdRelease Notes
News mentions
0No linked articles in our index yet.