Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-56610
HistoryJul 13, 2022 - 12:00 a.m.

csm path traversal vulnerability

2022-07-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
csm
open source
automation
orchestration
path traversal
vulnerability
flask
send_file
exploitation
attacker
arbitrary files
directories
file system
cnvd

EPSS

0.002

Percentile

62.0%

csm is a csm-aut open source automation and orchestration framework for IOS-XR devices. csm 3.5 and earlier versions have a path traversal vulnerability that stems from a failure of Flask’s send_file function to properly filter special elements in a resource or file path, which can be exploited by an attacker to access arbitrary files and directories stored on the file system.

EPSS

0.002

Percentile

62.0%

Related for CNVD-2022-56610