CVE-2021-41324: Path Traversal
Published Sep 30, 2021
·Updated
Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete).
Affected Software
2 affected components
Pydio Cells=2.2.9
Pydio Cells=2.2.9
Event History
Sep 30, 2021
CVE Published
via MITRE·08:39 PM
Data Sourced
via MITRE·08:39 PM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Pydio Cells vulnerability?
The vulnerability ID for this Pydio Cells vulnerability is CVE-2021-41324.
2
What is the severity of CVE-2021-41324?
The severity of CVE-2021-41324 is medium, with a severity value of 6.5.
3
What is the affected software version of CVE-2021-41324?
The affected software version of CVE-2021-41324 is Pydio Cells 2.2.9.
4
How does the vulnerability in Pydio Cells 2.2.9 allow remote authenticated users to enumerate personal files?
The vulnerability in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files by exploiting directory traversal in the Copy, Move, and Delete features.
5
What are the recommended fixes for CVE-2021-41324?
To fix CVE-2021-41324, it is recommended to update Pydio Cells to version 2.2.12 or later.