CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (9,901)
page 461 of 496| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-11498 | Hig | 0.00 | 8.8 | 0.03 | Apr 2, 2020 | Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for… | ||
| CVE-2020-10696 | Hig | 0.00 | 8.8 | 0.03 | Mar 31, 2020 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. | ||
| CVE-2020-8131 | Hig | 0.00 | 7.5 | 0.05 | Feb 24, 2020 | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package. | ||
| CVE-2020-8545 | Hig | 0.00 | 7.5 | 0.01 | Feb 3, 2020 | Global.py in AIL framework 2.8 allows path traversal. | ||
| CVE-2020-5221 | Med | 0.00 | 6.5 | 0.01 | Jan 22, 2020 | In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has… | ||
| CVE-2019-11246 | Med | 0.00 | 6.5 | 0.04 | Aug 29, 2019 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in… | ||
| CVE-2019-15520 | Med | 0.00 | 5.3 | 0.02 | Aug 23, 2019 | comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory. | ||
| CVE-2019-15519 | Cri | 0.00 | 9.8 | 0.03 | Aug 23, 2019 | Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. | ||
| CVE-2019-15518 | Med | 0.00 | 5.3 | 0.02 | Aug 23, 2019 | Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. | ||
| CVE-2019-15517 | — | Med | 0.00 | 5.5 | 0.01 | Aug 23, 2019 | jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. | |
| CVE-2019-15516 | Hig | 0.00 | 7.5 | 0.02 | Aug 23, 2019 | Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring. | ||
| CVE-2019-10185 | Hig | 0.00 | 8.6 | 0.04 | Jul 31, 2019 | It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and,… | ||
| CVE-2019-10182 | Hig | 0.00 | 8.2 | 0.03 | Jul 31, 2019 | It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the… | ||
| CVE-2019-14452 | Hig | 0.00 | 7.5 | 0.04 | Jul 31, 2019 | Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. | ||
| CVE-2019-10152 | Hig | 0.00 | 7.2 | 0.00 | Jul 30, 2019 | A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator… | ||
| CVE-2018-17180 | Med | 0.00 | 5.3 | 0.02 | May 17, 2019 | An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php. | ||
| CVE-2019-5624 | Hig | 0.00 | 7.3 | 0.03 | Apr 30, 2019 | Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at… | ||
| CVE-2019-9889 | Low | 0.00 | 2.7 | 0.02 | Mar 21, 2019 | In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code… | ||
| CVE-2019-9195 | Cri | 0.00 | 9.8 | 0.04 | Feb 26, 2019 | util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive. | ||
| CVE-2018-20332 | Hig | 0.00 | 7.5 | 0.02 | Dec 21, 2018 | An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and listing of arbitrary directories is possible with /file?action=download&dir=… |
- risk 0.00cvss 8.8epss 0.03
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for…
- risk 0.00cvss 8.8epss 0.03
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
- risk 0.00cvss 7.5epss 0.05
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
- risk 0.00cvss 7.5epss 0.01
Global.py in AIL framework 2.8 allows path traversal.
- risk 0.00cvss 6.5epss 0.01
In uftpd before 2.11, it is possible for an unauthenticated user to perform a directory traversal attack using multiple different FTP commands and read and write to arbitrary locations on the filesystem due to the lack of a well-written chroot jail in compose_abspath(). This has…
- risk 0.00cvss 6.5epss 0.04
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in…
- risk 0.00cvss 5.3epss 0.02
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
- risk 0.00cvss 9.8epss 0.03
Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin.
- risk 0.00cvss 5.3epss 0.02
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
- risk 0.00cvss 5.5epss 0.01
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal.
- risk 0.00cvss 7.5epss 0.02
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring.
- risk 0.00cvss 8.6epss 0.04
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attacker could use this flaw to write files to arbitrary locations. This could also be used to replace the main running application and,…
- risk 0.00cvss 8.2epss 0.03
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the…
- risk 0.00cvss 7.5epss 0.04
Sigil before 0.9.16 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction.
- risk 0.00cvss 7.2epss 0.00
A path traversal vulnerability has been discovered in podman before version 1.4.0 in the way it handles symlinks inside containers. An attacker who has compromised an existing container can cause arbitrary files on the host filesystem to be read/written when an administrator…
- risk 0.00cvss 5.3epss 0.02
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php.
- risk 0.00cvss 7.3epss 0.03
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at…
- risk 0.00cvss 2.7epss 0.02
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can leverage this vulnerability to execute code…
- risk 0.00cvss 9.8epss 0.04
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
- risk 0.00cvss 7.5epss 0.02
An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and listing of arbitrary directories is possible with /file?action=download&dir=…