PT-2023-22234 · Unknown · Warpinator

·

CVE-2023-29380

·

Publicado

2023-04-27

·

Atualizado

2025-01-13

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Warpinator versions prior to 1.6.0
Description The issue allows remote file deletion via directory traversal in top dir basenames. This could enable an attacker to delete arbitrary files on the recipient's computer. The vulnerability has been fixed in Warpinator 1.6.0, which also includes additional protection against similar issues through the use of file system isolation using Landlock or Bubblewrap.
Recommendations For versions prior to 1.6.0, update to Warpinator 1.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the top dir basenames directory to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-29380

Produtos afetados

Warpinator