Lucene search

K
cvelistSnykCVELIST:CVE-2022-21221
HistoryMar 17, 2022 - 11:21 a.m.

CVE-2022-21221 Directory Traversal

2022-03-1711:21:09
snyk
www.cve.org
3
package vulnerability
improper sanitization
exploitation
windows users
servefile function

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.6%

The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. Note: This security issue impacts Windows users only.

CNA Affected

[
  {
    "product": "github.com/valyala/fasthttp",
    "vendor": "n/a",
    "versions": [
      {
        "lessThan": "1.34.0",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

61.6%

Related for CVELIST:CVE-2022-21221