PT-2018-4157 · Inert · Inert
Published
2018-05-29
·
Updated
2020-08-31
·
CVE-2014-10068
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
inert versions prior to 1.1.1
Description
The issue concerns an information leakage problem where files in hidden directories are served even when
showHidden is set to false. This is due to the inert directory handler always allowing access to these files, regardless of the showHidden setting.Recommendations
Update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to hidden directories until the update is applied.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Inert