CVE-2022-21132: Path Traversal
Published Mar 7, 2022
·Updated
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.54 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.61 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
Affected Software
2 affected components
pfSense pfSense-pkg-WireGuard>=0.1.5<0.1.5_4
pfSense pfSense-pkg-WireGuard=0.1.6
Remediation
Event History
Mar 7, 2022
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-21132?
CVE-2022-21132 is a directory traversal vulnerability in pfSense-pkg-WireGuard.
2
What is the severity of CVE-2022-21132?
The severity of CVE-2022-21132 is medium with a CVSS score of 6.5.
3
How does CVE-2022-21132 affect pfSense-pkg-WireGuard?
CVE-2022-21132 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
4
What versions of pfSense-pkg-WireGuard are affected by CVE-2022-21132?
CVE-2022-21132 affects pfSense-pkg-WireGuard versions prior to 0.1.5_4 and 0.1.6.
5
How can I fix CVE-2022-21132 in pfSense-pkg-WireGuard?
To fix CVE-2022-21132, upgrade pfSense-pkg-WireGuard to version 0.1.5_4 or 0.1.6_1.