PT-2020-7947 · Unknown · Fury-Adapter-Swagger

Published

2020-09-01

·

Updated

2020-09-01

·

CVE-2016-1000249

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: fury-adapter-swagger versions 0.2.0 through 0.9.7
Description: The issue allows an attacker to read arbitrary files off the system, potentially leading to the exposure of sensitive data or causing a denial of service condition by attempting to read files like /dev/zero.
Recommendations: For versions 0.2.0 through 0.9.7, upgrade to version 0.9.7 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1000249
GHSA-2R7F-4H2C-5X73

Affected Products

Fury-Adapter-Swagger