PT-2019-6692 · Yaws · Yaws
Jan Lieskovsky
·
Published
2019-11-26
·
Updated
2020-08-18
·
CVE-2011-4350
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Yaws version 1.91
Description
The issue arises from the way certain URLs are processed, allowing a remote authenticated user to exploit a directory traversal flaw. This could enable the user to obtain the content of arbitrary local files by sending specially-crafted URL requests.
Recommendations
For Yaws version 1.91, consider restricting access to sensitive local files until a patch is available. As a temporary workaround, carefully validate and sanitize all URL requests to prevent directory traversal attacks.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yaws