CVE-2015-5638: Path Traversal
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5638?
CVE-2015-5638 is classified as a medium severity vulnerability due to its potential to allow arbitrary file reading on affected systems.
How do I fix CVE-2015-5638?
To fix CVE-2015-5638, upgrade H2O to version 1.4.5 or 1.5.0-beta2 or later where the vulnerability is patched.
What causes the CVE-2015-5638 vulnerability?
The CVE-2015-5638 vulnerability is caused by a directory traversal weakness in H2O when the file.dir directive is enabled.
Who is affected by CVE-2015-5638?
CVE-2015-5638 affects H2O versions prior to 1.4.5 and versions in the 1.5.x series before 1.5.0-beta2.
What can attackers do exploiting CVE-2015-5638?
Attackers exploiting CVE-2015-5638 can read arbitrary files on the server by crafting specific URLs.