PT-2019-12037 · Iobroker · Iobroker.Admin

Fabio Carretto

·

Published

2019-11-20

·

Updated

2020-09-04

·

CVE-2019-10765

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iobroker.admin versions prior to 3.6.12
Description The issue allows an attacker to include file contents from outside the intended directory due to a path traversal problem. The package fails to restrict access to folders outside of the intended folder in the /log/ route, which may allow attackers to include arbitrary files in the system. An attacker would need to be authenticated to perform the attack, but the package has authentication disabled by default.
Recommendations Upgrade to version 3.6.12 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10765
GHSA-54XJ-Q58H-9X57
SNYK-JS-IOBROKERADMIN-534634

Affected Products

Iobroker.Admin