← volver
CVE-2022-23082highCWE-22

CureKit - Path Traversal in isFileOutsideDir

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 7.5epss 1.3%
probabilidad de explotación
1.3%top 30% de las CVE
explotación observada
noninguna fuente lo reporta
In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
WhiteSource · CureKit