PT-2022-27633 · Unknown · Ubi Reader

Qkaiser

·

Published

2022-12-17

·

Updated

2022-12-22

·

CVE-2022-4572

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions UBI Reader versions up to 0.8.0
Description A vulnerability has been found in the UBIFS File Handler component, specifically affecting the ubireader extract files function of the file ubireader/ubifs/output.py. This issue leads to path traversal and can be exploited remotely.
Recommendations For UBI Reader versions up to 0.8.0, upgrade to version 0.8.5 to address this issue. As a temporary workaround, consider restricting access to the ubireader extract files function until the upgrade is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-4572
GHSA-HC37-84V3-8GMQ
PYSEC-2022-43016

Affected Products

Ubi Reader