CVE-2018-0673: Path Traversal
Published Nov 15, 2018
·Updated
Directory traversal vulnerability in Cybozu Garoon 3.5.0 to 4.6.3 allows authenticated attackers to read arbitrary files via unspecified vectors.
Affected Software
1 affected component
Cybozu Garoon>=3.5.0<=4.6.3
Event History
Nov 15, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-0673?
CVE-2018-0673 is classified as a medium severity directory traversal vulnerability.
2
How do I fix CVE-2018-0673?
To mitigate CVE-2018-0673, update Cybozu Garoon to a version later than 4.6.3.
3
Which versions of Cybozu Garoon are affected by CVE-2018-0673?
CVE-2018-0673 affects Cybozu Garoon versions from 3.5.0 to 4.6.3.
4
Can unauthorized users exploit CVE-2018-0673?
No, CVE-2018-0673 requires authentication to exploit the directory traversal vulnerability.
5
What kind of files can be read due to CVE-2018-0673?
CVE-2018-0673 allows authenticated attackers to read arbitrary files on the server.