PT-2023-22234 · Unknown · Warpinator
Matthias Gerstner
·
Published
2023-04-27
·
Updated
2025-01-13
·
CVE-2023-29380
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Warpinator versions prior to 1.6.0
Description
The issue allows remote file deletion via directory traversal in top dir basenames. This could enable an attacker to delete arbitrary files on the recipient's computer. The vulnerability has been fixed in Warpinator 1.6.0, which also includes additional protection against similar issues through the use of file system isolation using Landlock or Bubblewrap.
Recommendations
For versions prior to 1.6.0, update to Warpinator 1.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the
top dir basenames directory to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Warpinator