PT-2022-13954 · Clinical Genomics · Scout-Browser+1
Published
2022-05-03
·
Updated
2022-05-10
·
CVE-2022-1554
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
clinical-genomics/scout versions prior to 4.52
Description
The issue is related to a Path Traversal vulnerability due to a
send file call in the clinical-genomics/scout GitHub repository. This vulnerability affects the Scout software, which is a Variant Call Format (VCF) visualization interface. The scout-browser Pypi package is also vulnerable to this issue.Recommendations
For versions prior to 4.52, update to version 4.52 or later to resolve the issue. As a temporary workaround, consider restricting access to the
send file call to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scout
Scout-Browser