Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36564
HistoryAug 02, 2022 - 9:27 a.m.

Directory Traversal

2022-08-0209:27:24
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
directory traversal
sanic
url paths
_handler function
app.static
encoded urls

EPSS

0.001

Percentile

45.5%

sanic is vulnerable to directory traversal. The vulnerability exists due to a lack of sanitization of URL paths in the _handler function allowing an attacker to access lateral directories when using app.static if using encoded %2F URLs.

EPSS

0.001

Percentile

45.5%

Related for VERACODE:36564