Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:30044
HistoryApr 20, 2021 - 6:25 a.m.

Directory Traversal

2021-04-2006:25:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.004 Low

EPSS

Percentile

72.6%

flow-server is vulnerable to directory traversal. The attack is possible due to a lack of proper validation of URL path, allowing an attacker to inject ../ characters into in parameters to access resources outside of the web root.

CPENameOperatorVersion
flow serverle4.0.5
flow serverle2.4.0

0.004 Low

EPSS

Percentile

72.6%