First published: Fri Oct 15 2021(Updated: )
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Bookstackapp Bookstack | <21.08.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3874 is a vulnerability that affects bookstack, allowing for improper limitation of a pathname to a restricted directory (path traversal).
CVE-2021-3874 has a severity score of 6.5, which is considered medium.
The bookstack software up to version 21.08.5 is affected by CVE-2021-3874.
To fix CVE-2021-3874, it is recommended to update your bookstack software to a version that includes the fix for this vulnerability.
You can find more information about CVE-2021-3874 in the references provided: [GitHub commit](https://github.com/bookstackapp/bookstack/commit/7224fbcc89f00f2b71644e36bb1b1d96addd1d5a) and [Huntr.dev](https://huntr.dev/bounties/ac268a17-72b5-446f-a09a-9945ef58607a).