PT-2021-23158 · Mycodo · Mycodo

Haby0

·

Published

2021-10-26

·

Updated

2021-10-27

·

CVE-2021-41185

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mycodo versions prior to 8.12.7
Description Mycodo is an environmental monitoring and regulation system. An exploit allows anyone with access to endpoints to download files outside the intended directory. A patch has been applied and a release made.
Recommendations For versions prior to 8.12.7, upgrade to version 8.12.7. As a temporary workaround, users may manually apply the changes from the fix commit.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41185
GHSA-252R-94PH-M229

Affected Products

Mycodo