VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 36 of 520
  • CVE-2022-31555CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31554CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31553CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31552CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31551CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31550CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31548CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31547CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31546CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31545CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31544CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31543CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31542CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31541CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31540CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31539CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31538CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31537CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31536CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31535CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.