CVE-2022-31520: Path Traversal
Published Jul 11, 2022
·Updated
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask sendfile function is used unsafely.
Affected Software
1 affected component
Logstash-management-api Project Logstash-management-api<=2020-05-04
Event History
Jul 11, 2022
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31520?
CVE-2022-31520 is categorized as a high severity vulnerability due to its potential for absolute path traversal.
2
How do I fix CVE-2022-31520?
To fix CVE-2022-31520, update your version of the logstash-management-api to a release after 2020-05-04.
3
What type of vulnerability is CVE-2022-31520?
CVE-2022-31520 is an absolute path traversal vulnerability affecting the logstash-management-api.
4
Who is affected by CVE-2022-31520?
Users of the logstash-management-api version 2020-05-04 and earlier are affected by CVE-2022-31520.
5
What potential impact does CVE-2022-31520 have?
CVE-2022-31520 could allow an attacker to read unauthorized files from the server's file system.