VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,483)

page 276 of 525
  • CVE-2020-2277MedSep 16, 2020
    risk 0.42cvss 6.5epss 0.02

    Jenkins Storable Configs Plugin 1.0 and earlier allows users with Job/Read permission to read arbitrary files on the Jenkins controller.

  • CVE-2020-2275MedSep 16, 2020
    risk 0.42cvss 6.5epss 0.02

    Jenkins Copy data to workspace Plugin 1.0 and earlier does not limit which directories can be copied from the Jenkins controller to job workspaces, allowing attackers with Job/Configure permission to read arbitrary files on the Jenkins controller.

  • CVE-2020-4711MedSep 15, 2020
    risk 0.42cvss 6.5epss 0.03

    IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 187501.

  • CVE-2019-20916HigSep 4, 2020
    risk 0.42cvss 7.5epss 0.03

    The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in…

  • CVE-2020-25032HigAug 31, 2020
    risk 0.42cvss 7.5epss 0.04

    An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.

  • CVE-2020-3440MedAug 26, 2020
    risk 0.42cvss 6.5epss 0.03

    A vulnerability in Cisco Webex Meetings Desktop App for Windows could allow an unauthenticated, remote attacker to overwrite arbitrary files on an end-user system. The vulnerability is due to improper validation of URL parameters that are sent from a website to the affected…

  • CVE-2020-7684HigJul 17, 2020
    risk 0.42cvss 7.5epss 0.01

    This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.

  • CVE-2020-3401MedJul 16, 2020
    risk 0.42cvss 6.5epss 0.03

    A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient…

  • CVE-2020-5581MedJun 30, 2020
    risk 0.42cvss 6.5epss 0.02

    Path traversal vulnerability in Cybozu Garoon 4.0.0 to 5.0.1 allows remote authenticated attackers to obtain unintended information via unspecified vectors.

  • CVE-2020-7667HigJun 24, 2020
    risk 0.42cvss 7.5epss 0.02

    In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit…

  • CVE-2020-7668HigJun 23, 2020
    risk 0.42cvss 7.5epss 0.01

    In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

  • CVE-2020-7664HigJun 23, 2020
    risk 0.42cvss 7.5epss 0.01

    In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

  • CVE-2020-3241MedJun 18, 2020
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the orchestration tasks of Cisco UCS Director could allow an authenticated, remote attacker to perform a path traversal attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input on the web-based management…

  • CVE-2019-16384MedJun 4, 2020
    risk 0.42cvss 6.5epss 0.01

    Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.

  • CVE-2020-7650MedMay 29, 2020
    risk 0.42cvss 6.5epss 0.01

    All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.

  • CVE-2020-7648MedMay 29, 2020
    risk 0.42cvss 6.5epss 0.01

    All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`

  • CVE-2020-7652MedMay 29, 2020
    risk 0.42cvss 6.5epss 0.02

    All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.

  • CVE-2020-12737MedMay 8, 2020
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Maxum Rumpus before 8.2.12 on macOS. Authenticated users can perform a path traversal using double escaped characters, enabling read access to arbitrary files on the server.

  • CVE-2019-18870MedMay 7, 2020
    risk 0.42cvss 6.5epss 0.01

    A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.

  • CVE-2020-11420MedApr 27, 2020
    risk 0.42cvss 6.5epss 0.02

    UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and directories outside the web root folder. An…