PT-2026-102394 · Dozzle · Dozzle
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Dozzle versions prior to 11.1.2
Description
Insufficient sanitization of container display names occurs when building ZIP archive entry names in the log download endpoint. Attackers with the ability to label containers can employ path traversal sequences—a technique used to access files and directories outside the intended folder—to write files outside the extraction directory when users download and extract logs.
Recommendations
Update to version 11.1.2 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dozzle