PT-2022-14868 · Pfsense · Pfsense-Pkg-Wireguard

Yutaka Watanabe

·

Published

2022-03-07

·

Updated

2022-03-15

·

CVE-2022-21132

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pfSense-pkg-WireGuard versions 0.1.5 through 0.1.5 3 pfSense-pkg-WireGuard versions 0.1.6 through 0.1.6 0
Description A directory traversal issue allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
Recommendations For pfSense-pkg-WireGuard versions 0.1.5 through 0.1.5 3, update to version 0.1.5 4 or later. For pfSense-pkg-WireGuard versions 0.1.6 through 0.1.6 0, update to version 0.1.6 1 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-21132

Affected Products

Pfsense-Pkg-Wireguard