We found results for “”
WS-2021-0195
Good to know:
Date: April 14, 2021
Aah in versions v0.12.0 to v0.12.3 is allowing an attacker to read files outside of the target directory that the server has permission to read. Related to http_engine.go and static.go
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Path Traversal
CWE-22Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |