CVE-2021-35397: Input Validation
A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identifier for this issue?
The vulnerability identifier for this issue is CVE-2021-35397.
What is the severity of CVE-2021-35397?
The severity of CVE-2021-35397 is high with a CVSS score of 7.5.
Which versions of Drogon are affected by CVE-2021-35397?
Drogon versions 1.0.0-beta14 to 1.6.0 are affected by CVE-2021-35397.
How can an attacker exploit CVE-2021-35397?
An attacker can exploit CVE-2021-35397 by using a path traversal technique to read arbitrary files on the system.
Is authentication required for the exploitation of CVE-2021-35397?
No, CVE-2021-35397 can be exploited by an unauthenticated, remote attacker.