CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 481 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-36065 | Hig | 0.00 | 7.5 | 0.01 | Sep 6, 2022 | GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new accounts and upload files to arbitrary directories within the container. If the attacker uploads a Python… | ||
| CVE-2022-2653 | Med | 0.00 | 6.5 | 0.01 | Aug 4, 2022 | With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able… | ||
| CVE-2022-36889 | Hig | 0.00 | 8.8 | 0.02 | Jul 27, 2022 | Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the… | ||
| CVE-2022-35861 | Hig | 0.00 | 7.8 | 0.00 | Jul 17, 2022 | pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a Python version string in .python-version to execute shims under their control. (Shims are executables that pass a command along… | ||
| CVE-2022-31564 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31549 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31510 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31508 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31504 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31503 | Cri | 0.00 | 9.3 | 0.02 | Jul 11, 2022 | The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31502 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31501 | Cri | 0.00 | 9.3 | 0.01 | Jul 11, 2022 | The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31372 | Hig | 0.00 | 7.5 | 0.01 | Jun 16, 2022 | Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler. | ||
| CVE-2022-1721 | Hig | 0.00 | 7.5 | 0.02 | May 16, 2022 | Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application. | ||
| CVE-2022-24830 | Med | 0.00 | 6.5 | 0.03 | May 14, 2022 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There… | ||
| CVE-2022-28451 | Hig | 0.00 | 7.5 | 0.02 | May 2, 2022 | nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. | ||
| CVE-2022-26068 | Med | 0.00 | 6.5 | 0.02 | May 1, 2022 | This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server. | ||
| CVE-2022-25842 | Med | 0.00 | 6.9 | 0.04 | May 1, 2022 | All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable… | ||
| CVE-2022-29967 | Hig | 0.00 | 7.5 | 0.02 | Apr 29, 2022 | static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal. | ||
| CVE-2022-24851 | Hig | 0.00 | 8.1 | 0.01 | Apr 15, 2022 | LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated… |
- risk 0.00cvss 7.5epss 0.01
GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new accounts and upload files to arbitrary directories within the container. If the attacker uploads a Python…
- risk 0.00cvss 6.5epss 0.01
With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able…
- risk 0.00cvss 8.8epss 0.02
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the…
- risk 0.00cvss 7.8epss 0.00
pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a Python version string in .python-version to execute shims under their control. (Shims are executables that pass a command along…
- risk 0.00cvss 9.3epss 0.01
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.02
The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 9.3epss 0.01
The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.00cvss 7.5epss 0.01
Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.
- risk 0.00cvss 7.5epss 0.02
Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application.
- risk 0.00cvss 6.5epss 0.03
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There…
- risk 0.00cvss 7.5epss 0.02
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
- risk 0.00cvss 6.5epss 0.02
This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.
- risk 0.00cvss 6.9epss 0.04
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable…
- risk 0.00cvss 7.5epss 0.02
static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.
- risk 0.00cvss 8.1epss 0.01
LDAP Account Manager (LAM) is an open source web frontend for managing entries stored in an LDAP directory. The profile editor tool has an edit profile functionality, the parameters on this page are not properly sanitized and hence leads to stored XSS attacks. An authenticated…