PT-2017-6660 · Etherpad · Etherpad

Tom Hunkapiller

·

Publicado

2017-07-07

·

Atualizado

2020-02-14

·

CVE-2015-3297

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Etherpad versions 1.1.1 through 1.5.2
Description The issue allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests, such as "/api/*" endpoints.
Recommendations For versions 1.1.1 through 1.5.2, as a temporary workaround, consider restricting access to the Minify.js file in the node/utils directory until a patch is available. Avoid using the path parameter in affected API endpoints until the issue is resolved.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-3297

Produtos afetados

Etherpad