PT-2022-13954 · Clinical Genomics · Scout-Browser+1

Published

2022-05-03

·

Updated

2022-05-10

·

CVE-2022-1554

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions clinical-genomics/scout versions prior to 4.52
Description The issue is related to a Path Traversal vulnerability due to a send file call in the clinical-genomics/scout GitHub repository. This vulnerability affects the Scout software, which is a Variant Call Format (VCF) visualization interface. The scout-browser Pypi package is also vulnerable to this issue.
Recommendations For versions prior to 4.52, update to version 4.52 or later to resolve the issue. As a temporary workaround, consider restricting access to the send file call to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1554
GHSA-694V-63FQ-FMR4

Affected Products

Scout
Scout-Browser