Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Robotdan

#37394of 53,622
7.5Total CVSS
Vulnerabilities · 1
PT-2022-27687
7.5
2022-11-28
Unknown · Fusionauth · CVE-2022-45921
**Name of the Vulnerable Software and Affected Versions** FusionAuth versions prior to 1.41.3 **Description** The issue allows an attacker to view or retrieve files outside of the application root using an HTTP request. Specifically, an attacker may be able to access any file readable by the user running the FusionAuth process. **Recommendations** For versions prior to 1.41.3, update to version 1.41.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.