Path Traversal Vulnerability in WindMill Repository by Lukasavicus
CVE-2022-31519

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
11 July 2022

What is CVE-2022-31519?

A vulnerability exists in the WindMill repository by Lukasavicus that allows attackers to exploit absolute path traversal due to improper use of the Flask send_file function. This flaw could enable unauthorized access to system files, posing risks to data integrity and confidentiality. It underscores the importance of securing file retrieval mechanisms in web applications.

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.