PT-2022-20775 · Unknown+1 · Opendiamond+1

Ghost

·

Published

2022-07-11

·

Updated

2022-07-15

·

CVE-2022-31506

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions cmusatyalab/opendiamond versions through 10.1.1
Description The issue allows absolute path traversal due to the unsafe use of the Flask send file function. A patch is available on the master branch of the repository.
Recommendations For versions through 10.1.1, update to the patched version available on the master branch of the repository. As a temporary workaround, consider restricting access to the send file function until the patch is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31506
GHSA-X2PC-FQRW-HC7F

Affected Products

Flask
Opendiamond