VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 482 of 520
  • CVE-2021-43290CriApr 14, 2022
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a directory that they can't control.

  • CVE-2021-43289HigApr 14, 2022
    risk 0.00cvss 7.5epss 0.02

    An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

  • CVE-2021-26601HigMar 28, 2022
    risk 0.00cvss 8.1epss 0.03

    ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

  • CVE-2022-24774HigMar 22, 2022
    risk 0.00cvss 7.1epss 0.01

    CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit…

  • CVE-2022-1000CriMar 17, 2022
    risk 0.00cvss 9.8epss 0.02

    Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

  • CVE-2021-29134MedMar 15, 2022
    risk 0.00cvss 5.3epss 0.01

    The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.

  • CVE-2022-23612HigFeb 22, 2022
    risk 0.00cvss 7.5epss 0.02

    OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions are subject to arbitrary file exfiltration due to failure to sanitize request when satisfying GET requests for `/images` &…

  • CVE-2022-25358MedFeb 18, 2022
    risk 0.00cvss 5.3epss 0.01

    A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only list directories (not read files). This occurs because the safe-path? Scheme predicate is not used for directories.

  • CVE-2022-0673MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.

  • CVE-2022-25298HigFeb 18, 2022
    risk 0.00cvss 7.5epss 0.02

    This affects the package sprinfall/webcc before 0.3.0. It is possible to traverse directories to fetch arbitrary files from the server.

  • CVE-2022-22931MedFeb 7, 2022
    risk 0.00cvss 4.3epss 0.02

    Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - maildir mailbox store - Sieve file repository This enables a user to access other users data stores (limited to user names being prefixed by the value of the…

  • CVE-2022-23609HigFeb 4, 2022
    risk 0.00cvss 8.3epss 0.01

    iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize user input used to remove files leading to file deletion only limited by the process permissions. Users are advised to upgrade as…

  • CVE-2022-23602HigFeb 1, 2022
    risk 0.00cvss 7.7epss 0.01

    Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum will render the file if able. This can also be done silently…

  • CVE-2021-23520MedJan 31, 2022
    risk 0.00cvss 5.5epss 0.01

    The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when the archive is extracted upon calling uncompressTo() on a…

  • CVE-2022-22932MedJan 26, 2022
    risk 0.00cvss 5.3epss 0.03

    Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by user. This has been fixed in revision:…

  • CVE-2020-19858HigJan 21, 2022
    risk 0.00cvss 7.5epss 0.02

    Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy.

  • CVE-2022-21682HigJan 13, 2022
    risk 0.00cvss 7.7epss 0.02

    Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that…

  • CVE-2021-23514MedJan 13, 2022
    risk 0.00cvss 6.5epss 0.02

    This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server.

  • CVE-2022-23107HigJan 12, 2022
    risk 0.00cvss 8.1epss 0.02

    Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the Jenkins controller file system.

  • CVE-2022-21675CriJan 12, 2022
    risk 0.00cvss 9.9epss 0.03

    Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially crafted archive that holds directory…