First published: Thu Oct 27 2022(Updated: )
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1
Credit: psirt@paloaltonetworks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Litespeedtech Openlitespeed | >=1.6.5<=1.6.20.1 | |
Litespeedtech Openlitespeed | >=1.7.0<1.7.16.1 | |
Litespeedtech Openlitespeed | =1.5.11 | |
Litespeedtech Openlitespeed | =1.5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0072 is classified as a medium-severity directory traversal vulnerability.
To fix CVE-2022-0072, upgrade your OpenLiteSpeed or LiteSpeed Web Server to version 1.7.16.1 or later, or to versions 1.5.13 or 1.6.21 and above.
CVE-2022-0072 affects OpenLiteSpeed versions 1.5.11 to 1.5.12, 1.6.5 to 1.6.20.1, and 1.7.0 up to, but not including, 1.7.16.1.
CVE-2022-0072 is a directory traversal vulnerability that allows unauthorized access to files on the web server.
An attacker exploiting CVE-2022-0072 could potentially access sensitive files on the server, posing a serious security risk.