Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56604
HistoryJul 13, 2022 - 12:00 a.m.

Barry-Voice-Assistant path traversal vulnerability

2022-07-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
barry-voice-assistant
bulgarian
lyuboslav karev
flask
send_file function
path traversal
vulnerability
arbitrary files
directories
file system
exploit
cnvd

EPSS

0.002

Percentile

62.0%

Barry-Voice-Assistant is a voice assistant from the Bulgarian personal developer Lyuboslav Karev. Barry-Voice-Assistant 2021-01-18 and earlier versions have a path traversal vulnerability, which stems from the failure of Flask’s send_file function to properly filter special elements in resource or file paths, and can be exploited to access arbitrary files and directories stored on the file system.

EPSS

0.002

Percentile

62.0%

Related for CNVD-2022-56604