PT-2018-4157 · Inert · Inert
Publicado
2018-05-29
·
Atualizado
2020-08-31
·
CVE-2014-10068
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
inert versions prior to 1.1.1
Description
The issue concerns an information leakage problem where files in hidden directories are served even when
showHidden is set to false. This is due to the inert directory handler always allowing access to these files, regardless of the showHidden setting.Recommendations
Update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to hidden directories until the update is applied.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Inert