CVE-2022-0072: Directory Traversal in OpenLiteSpeed Web Server
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-0072?
CVE-2022-0072 is classified as a medium-severity directory traversal vulnerability.
How do I fix CVE-2022-0072?
To fix CVE-2022-0072, upgrade your OpenLiteSpeed or LiteSpeed Web Server to version 1.7.16.1 or later, or to versions 1.5.13 or 1.6.21 and above.
Which versions are affected by CVE-2022-0072?
CVE-2022-0072 affects OpenLiteSpeed versions 1.5.11 to 1.5.12, 1.6.5 to 1.6.20.1, and 1.7.0 up to, but not including, 1.7.16.1.
What type of vulnerability is CVE-2022-0072?
CVE-2022-0072 is a directory traversal vulnerability that allows unauthorized access to files on the web server.
What could an attacker do with CVE-2022-0072?
An attacker exploiting CVE-2022-0072 could potentially access sensitive files on the server, posing a serious security risk.