Directory Traversal Vulnerability in Druid by Alibaba
CVE-2021-33800
7.5HIGH
What is CVE-2021-33800?
In Druid version 1.2.3, there exists a vulnerability that enables attackers to perform directory traversal by manipulating parameters in specific function paths. If exploited, this could allow unauthorized access to sensitive files on the server, potentially compromising the security of the application.
Affected Version(s)
Druid 1.2.3
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
