CVE-2022-2653: Path Traversal in plankanban/planka
With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able to read any file in the system.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-2653?
CVE-2022-2653 is considered a critical vulnerability due to the potential exposure of sensitive files and database credentials.
How do I fix CVE-2022-2653?
To fix CVE-2022-2653, upgrade Planka to version 1.5.1 or later where the vulnerability has been addressed.
What types of files can be accessed due to CVE-2022-2653?
An attacker exploiting CVE-2022-2653 can read sensitive files such as configuration files and the /proc/self/environ file.
Who is affected by CVE-2022-2653?
CVE-2022-2653 affects any installation of Planka versions below 1.5.1.
What potential impact does CVE-2022-2653 have on web servers?
If exploited, CVE-2022-2653 may allow attackers to gain access to environment variables, potentially exposing database credentials and increasing the risk of further attacks.