Fides vulnerable to Path Traversal in Webserver API
CVE-2023-36827
What is CVE-2023-36827?
The Fides open-source privacy engineering platform has a path traversal vulnerability that affects versions earlier than 2.15.1. This allows remote attackers to potentially access arbitrary files within the Fides webserver container's filesystem. While the vulnerability is addressed in version 2.15.1, it can pose a significant risk if the Fides webserver API is exposed directly to attackers. To mitigate this risk, it is advisable to deploy Fides behind a reverse proxy, such as the AWS application load balancer, which will reject such attacks. Additionally, using environment variables for container secrets instead of the configuration file helps safeguard sensitive information from this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
fides < 2.15.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
