Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-38633
HistoryJul 22, 2023 - 5:15 p.m.

Directory traversal

2023-07-2217:15:00
PRIOn knowledge base
www.prio-n.com
7
directory traversal
url decoder
librsvg
vulnerability
remote attackers
local attackers
disclosure
file system

5.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.5%

A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=“.?../…/…/…/…/…/…/…/…/…/etc/passwd” in an xi:include element.