CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 35 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31580 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31579 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31577 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31576 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31575 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31574 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31573 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31572 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31571 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31568 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31567 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31565 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31563 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31562 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31561 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31560 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31559 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31558 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31557 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31556 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
- risk 0.61cvss 9.3epss 0.01
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.