PT-2017-6660 · Etherpad · Etherpad

Tom Hunkapiller

·

Published

2017-07-07

·

Updated

2020-02-14

·

CVE-2015-3297

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Etherpad versions 1.1.1 through 1.5.2
Description The issue allows remote attackers to read arbitrary files by leveraging replacement of backslashes with slashes in the path parameter of HTTP API requests, such as "/api/*" endpoints.
Recommendations For versions 1.1.1 through 1.5.2, as a temporary workaround, consider restricting access to the Minify.js file in the node/utils directory until a patch is available. Avoid using the path parameter in affected API endpoints until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3297

Affected Products

Etherpad