CVE-2021-35397: Input Validation

Published Aug 4, 2021
·
Updated

A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted.

Affected Software

10 affected components
Drogon Drogon>=1.1.0<=1.6.0
Drogon Drogon=1.0.0
Drogon Drogon=1.0.0-beta14
Drogon Drogon=1.0.0-beta15
Drogon Drogon=1.0.0-beta16
Drogon Drogon=1.0.0-beta17
Drogon Drogon=1.0.0-beta18
Drogon Drogon=1.0.0-beta19
Drogon Drogon=1.0.0-beta20
Drogon Drogon=1.0.0-beta21

Event History

Aug 4, 2021
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
Description

Frequently Asked Questions

1

What is the vulnerability identifier for this issue?

The vulnerability identifier for this issue is CVE-2021-35397.

2

What is the severity of CVE-2021-35397?

The severity of CVE-2021-35397 is high with a CVSS score of 7.5.

3

Which versions of Drogon are affected by CVE-2021-35397?

Drogon versions 1.0.0-beta14 to 1.6.0 are affected by CVE-2021-35397.

4

How can an attacker exploit CVE-2021-35397?

An attacker can exploit CVE-2021-35397 by using a path traversal technique to read arbitrary files on the system.

5

Is authentication required for the exploitation of CVE-2021-35397?

No, CVE-2021-35397 can be exploited by an unauthenticated, remote attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203