Lucene search

K
osvGoogleOSV:GHSA-69RR-WVH9-6C4Q
HistoryAug 31, 2020 - 10:58 p.m.

Directory Traversal in st

2020-08-3122:58:04
Google
osv.dev
13
st
directory traversal
vulnerability
update
software

EPSS

0.006

Percentile

78.1%

Versions of st prior to 0.2.5 are affected by a directory traversal vulnerability. Vulnerable versions fail to properly handle URL encoded dots, which caused %2e to be interpreted as . by the filesystem, resulting the potential for an attacker to read sensitive files on the server.

Recommendation

Update to version 0.2.5 or later.

EPSS

0.006

Percentile

78.1%