PT-2023-22234 · Unknown · Warpinator
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Warpinator versions prior to 1.6.0
Description
The issue allows remote file deletion via directory traversal in top dir basenames. This could enable an attacker to delete arbitrary files on the recipient's computer. The vulnerability has been fixed in Warpinator 1.6.0, which also includes additional protection against similar issues through the use of file system isolation using Landlock or Bubblewrap.
Recommendations
For versions prior to 1.6.0, update to Warpinator 1.6.0 to resolve the issue. As a temporary workaround, consider restricting access to the
top dir basenames directory to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Warpinator