Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-24843
HistoryApr 13, 2022 - 9:10 p.m.

CVE-2022-24843 Path Traversal in github.com/flipped-aurora/gin-vue-admin

2022-04-1321:10:16
CWE-22
GitHub_M
www.cve.org
2
gin-vue-admin
cve-2022-24843
path traversal
flaw
resolved

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

47.5%

Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin 2.50 has arbitrary file read vulnerability due to a lack of parameter validation. This has been resolved in version 2.5.1. There are no known workarounds for this issue.

CNA Affected

[
  {
    "product": "gin-vue-admin",
    "vendor": "flipped-aurora",
    "versions": [
      {
        "status": "affected",
        "version": "< 2.5.1"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

47.5%

Related for CVELIST:CVE-2022-24843