PT-2023-22234 · Unknown · Warpinator

Matthias Gerstner

·

Published

2023-04-27

·

Updated

2025-01-13

·

CVE-2023-29380

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Warpinator versions prior to 1.6.0
Description The issue allows remote file deletion via directory traversal in top dir basenames. This could enable an attacker to delete arbitrary files on the recipient's computer. The vulnerability has been fixed in Warpinator 1.6.0, which also includes additional protection against similar issues through the use of file system isolation using Landlock or Bubblewrap.
Recommendations For versions prior to 1.6.0, update to Warpinator 1.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the top dir basenames directory to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-29380

Affected Products

Warpinator