PT-2018-4157 · Inert · Inert

Publicado

2018-05-29

·

Atualizado

2020-08-31

·

CVE-2014-10068

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions inert versions prior to 1.1.1
Description The issue concerns an information leakage problem where files in hidden directories are served even when showHidden is set to false. This is due to the inert directory handler always allowing access to these files, regardless of the showHidden setting.
Recommendations Update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to hidden directories until the update is applied.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-10068
GHSA-G4XP-36C3-F7MR

Produtos afetados

Inert