VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 35 of 520
  • CVE-2022-31580CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31579CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31577CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31576CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31575CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31574CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31573CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31572CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31571CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31568CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31567CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31565CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31563CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31562CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31561CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31560CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31559CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31558CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31557CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31556CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.