CVE-2021-33896: Path Traversal
Published Jun 7, 2021
·Updated
Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.
Affected Software
4 affected components
Dino Dino<0.1.2
Dino Dino>=0.2.0<0.2.1
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Remediation
Patch Available
Patch Available
Event History
Jun 7, 2021
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
Description
Frequently Asked Questions
1
What is CVE-2021-33896?
CVE-2021-33896 is a vulnerability in the Dino software before versions 0.1.2 and 0.2.x before 0.2.1 that allows directory traversal during the creation of new files.
2
What is the severity of CVE-2021-33896?
CVE-2021-33896 has a severity value of 5.3, which is considered medium.
3
Which software versions are affected by CVE-2021-33896?
The Dino software versions before 0.1.2 and 0.2.x before 0.2.1 are affected by CVE-2021-33896.
4
What is the CWE ID associated with CVE-2021-33896?
CVE-2021-33896 is associated with CWE ID 22.
5
How can I fix CVE-2021-33896?
To fix CVE-2021-33896, update your Dino software to version 0.1.2 or 0.2.1 or later.