Lucene search

K
githubGitHub Advisory DatabaseGHSA-Q7MF-HP9M-CX6F
HistoryApr 29, 2022 - 2:59 a.m.

Roundup Directory traversal vulnerability

2022-04-2902:59:35
CWE-22
GitHub Advisory Database
github.com
5
roundup
directory traversal
remote attackers
http get request

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.5

Confidence

Low

EPSS

0.019

Percentile

88.8%

Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.

Affected configurations

Vulners
Node
rounduproundupRange0.6.4
VendorProductVersionCPE
rounduproundup*cpe:2.3:a:roundup:roundup:*:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.5

Confidence

Low

EPSS

0.019

Percentile

88.8%