VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (9,904)

page 458 of 496
  • CVE-2022-0673MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.

  • CVE-2022-25298HigFeb 18, 2022
    risk 0.00cvss 7.5epss 0.02

    This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files from the server.

  • CVE-2022-22931MedFeb 7, 2022
    risk 0.00cvss 4.3epss 0.02

    Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the…

  • CVE-2022-23609HigFeb 4, 2022
    risk 0.00cvss 8.3epss 0.01

    iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize user input used to remove files leading to file deletion only limited by the process permissions. Users are advised to upgrade as…

  • CVE-2022-23602HigFeb 1, 2022
    risk 0.00cvss 7.7epss 0.01

    Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently…

  • CVE-2021-23520MedJan 31, 2022
    risk 0.00cvss 5.5epss 0.01

    The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a…

  • CVE-2022-22932MedJan 26, 2022
    risk 0.00cvss 5.3epss 0.03

    Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision:…

  • CVE-2020-19858HigJan 21, 2022
    risk 0.00cvss 7.5epss 0.02

    Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.

  • CVE-2022-21682HigJan 13, 2022
    risk 0.00cvss 7.7epss 0.02

    Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that…

  • CVE-2021-23514MedJan 13, 2022
    risk 0.00cvss 6.5epss 0.02

    This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server.

  • CVE-2022-23107HigJan 12, 2022
    risk 0.00cvss 8.1epss 0.02

    Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

  • CVE-2022-21675CriJan 12, 2022
    risk 0.00cvss 9.9epss 0.03

    Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory…

  • CVE-2021-41242HigDec 10, 2021
    risk 0.00cvss 8.1epss 0.01

    OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is possible to create directory structures and…

  • CVE-2021-43800HigDec 6, 2021
    risk 0.00cvss 7.5epss 0.02

    Wiki.js is a wiki app built on Node.js. Prior to version 2.5.254, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled on a Windows host. A malicious user can potentially read any file on the file system by…

  • CVE-2021-44278CriDec 3, 2021
    risk 0.00cvss 9.8epss 0.01

    Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.

  • CVE-2021-3916MedNov 5, 2021
    risk 0.00cvss 6.5epss 0.01

    bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CVE-2019-3556HigOct 26, 2021
    risk 0.00cvss 8.1epss 0.02

    HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which…

  • CVE-2021-41185HigOct 26, 2021
    risk 0.00cvss 8.8epss 0.01

    Mycodo is an environmental monitoring and regulation system. An exploit in versions prior to 8.12.7 allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made. Users should upgrade to version 8.12.7. As a…

  • CVE-2021-41178HigOct 25, 2021
    risk 0.00cvss 8.8epss 0.02

    Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged…

  • CVE-2021-41152HigOct 18, 2021
    risk 0.00cvss 7.7epss 0.01

    OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning management system. In affected versions by manipulating the HTTP request an attacker can modify the path of a requested file download in the folder component to…