PT-2018-4157 · Inert · Inert

Published

2018-05-29

·

Updated

2020-08-31

·

CVE-2014-10068

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions inert versions prior to 1.1.1
Description The issue concerns an information leakage problem where files in hidden directories are served even when showHidden is set to false. This is due to the inert directory handler always allowing access to these files, regardless of the showHidden setting.
Recommendations Update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider restricting access to hidden directories until the update is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-10068
GHSA-G4XP-36C3-F7MR

Affected Products

Inert