PT-2017-11651 · Yaws · Yaws

Hyp3Rlinx

+1

·

Published

2017-07-07

·

Updated

2017-07-14

·

CVE-2017-10974

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yaws version 1.91
Description The issue allows unauthenticated remote file disclosure via HTTP directory traversal. This is achieved by using the //.. sequence to defeat traversal protection mechanisms. The vulnerability is specifically related to the use of an initial /%5C sequence.
Recommendations For Yaws version 1.91, consider restricting access to the HTTP endpoint on port 8080 as a temporary workaround until a patch is available. Avoid using the /%5C../ sequence in HTTP requests to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10974

Affected Products

Yaws