Arbitrary File Read Vulnerability in Kraken by Uber
CVE-2022-47747

7.5HIGH

Key Information:

Vendor

Uber

Status
Vendor
CVE Published:
20 January 2023

What is CVE-2022-47747?

An arbitrary file read vulnerability exists in Kraken versions up to 0.1.4, specifically through the testfs component. An attacker could exploit this vulnerability to read files on the server that should not be accessible, potentially leading to sensitive information exposure. Users of vulnerable versions are encouraged to apply necessary patches and upgrades to ensure their applications remain secure.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.