CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 37 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31534 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31533 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31532 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31531 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31530 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31529 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31528 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31527 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31526 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31525 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31524 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31523 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31522 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31521 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31520 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31519 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31518 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31517 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31516 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31515 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
- risk 0.61cvss 9.3epss 0.01
The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.