PT-2019-6692 · Yaws · Yaws

Jan Lieskovsky

·

Published

2019-11-26

·

Updated

2020-08-18

·

CVE-2011-4350

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Yaws version 1.91
Description The issue arises from the way certain URLs are processed, allowing a remote authenticated user to exploit a directory traversal flaw. This could enable the user to obtain the content of arbitrary local files by sending specially-crafted URL requests.
Recommendations For Yaws version 1.91, consider restricting access to sensitive local files until a patch is available. As a temporary workaround, carefully validate and sanitize all URL requests to prevent directory traversal attacks.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4350

Affected Products

Yaws