First published: Mon Mar 07 2022(Updated: )
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Pfsense Pfsense-pkg-wireguard | >=0.1.5<0.1.5_4 | |
Pfsense Pfsense-pkg-wireguard | =0.1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21132 is a directory traversal vulnerability in pfSense-pkg-WireGuard.
The severity of CVE-2022-21132 is medium with a CVSS score of 6.5.
CVE-2022-21132 allows a remote authenticated attacker to lead a pfSense user to view a file outside the public folder.
CVE-2022-21132 affects pfSense-pkg-WireGuard versions prior to 0.1.5_4 and 0.1.6.
To fix CVE-2022-21132, upgrade pfSense-pkg-WireGuard to version 0.1.5_4 or 0.1.6_1.