knowns before 0.30.0 Path Traversal via templateFile parameter
43Vexday Risk Score
Prioriza la corrección. Ella explotación observada por VulnCheck.
ssvc Actcvss 8.7epss 0.7%
de la publicación al arma
Publicada en NVD7 sept
VulnCheck+10d
probabilidad de explotación
0.7%top 47% de las CVE
explotación observada
síVulnCheck
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
knowns-dev · knownsReferencias
https://github.com/knowns-dev/knowns/blob/v0.29.1/internal/server/routes/templates.go#L299-L310https://github.com/knowns-dev/knowns/commit/09c5a96fd5817b941dc86669278c1a17db10ed4ehttps://github.com/knowns-dev/knowns/releases/tag/v0.30.0https://github.com/knowns-dev/knowns/security/advisories/GHSA-fpxv-c555-rhm3https://www.vulncheck.com/advisories/knowns-before-0.30.0-path-traversal-via-templatefile-parameter