Path Traversal Vulnerability in Bonn Activity Maps by GitHub
CVE-2022-31528

9.3CRITICAL

What is CVE-2022-31528?

The Bonn Activity Maps repository on GitHub has a vulnerability that permits absolute path traversal. This issue arises from the unsafe usage of the Flask send_file function, which could lead to unauthorized access to sensitive files outside the intended directory. This flaw can be exploited by attackers to manipulate file paths, potentially compromising the integrity and confidentiality of the server.

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.