Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40206
HistoryApr 20, 2023 - 7:58 a.m.

Directory Traversal

2023-04-2007:58:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
directory traversal
vulnerability
router.go
file download
host security
arbitrary file

0.001 Low

EPSS

Percentile

29.2%

github.com/gobbscom/go-bbs is vulnerable to Directory Traversal. The vulnerability exists in the init function of router.go, which allows an attacker to bypass file download restrictions through the /api/v1/download component and download arbitrary file from the host.

0.001 Low

EPSS

Percentile

29.2%

Related for VERACODE:40206