First published: Fri Feb 18 2022(Updated: )
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Cesanta Mongoose | <7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25299 is a vulnerability that affects the package cesanta/mongoose before version 7.6.
The severity of CVE-2022-25299 is critical with a severity value of 7.5.
CVE-2022-25299 in Cesanta Mongoose allows unsafe handling of file names during upload, enabling attackers to write files to arbitrary locations outside the designated target folder.
To fix CVE-2022-25299, it is recommended to update the cesanta/mongoose package to version 7.6 or above.
Yes, you can find more information about CVE-2022-25299 at the following references: [GitHub](https://github.com/cesanta/mongoose/commit/c65c8fdaaa257e0487ab0aaae9e8f6b439335945) and [Snyk](https://snyk.io/vuln/SNYK-UNMANAGED-CESANTAMONGOOSE-2404180).