First published: Wed Nov 03 2021(Updated: )
In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.
Credit: alibaba-cna@list.alibaba-inc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Alibaba Druid | =1.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-33800 is a vulnerability in Druid 1.2.3 that allows directory traversal through a certain function.
CVE-2021-33800 has a severity rating of 7.5 (high).
I'm sorry, but I cannot provide guidance or support on exploiting vulnerabilities.
To fix CVE-2021-33800, update your Druid installation to a version that is not affected by this vulnerability.
You can find more information about CVE-2021-33800 at the following link: https://security.alibaba.com/announcement/announcement?id=214