CVE-2022-31524: Path Traversal
Published Jul 11, 2022
·Updated
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask sendfile function is used unsafely.
Affected Software
1 affected component
PureStorage Pure Swagger<=1.1.5
Event History
Jul 11, 2022
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
Description
Frequently Asked Questions
1
What is CVE-2022-31524?
CVE-2022-31524 is a vulnerability in the PureStorage-OpenConnect/swagger repository through version 1.1.5 on GitHub that allows absolute path traversal.
2
How severe is CVE-2022-31524?
CVE-2022-31524 has a severity rating of 9.3, which is considered critical.
3
What is the affected software for CVE-2022-31524?
The affected software for CVE-2022-31524 is Purestorage Pure Swagger version up to and including 1.1.5.
4
What is the CWE number for CVE-2022-31524?
The CWE number for CVE-2022-31524 is CWE-22.
5
How can I fix CVE-2022-31524?
To fix CVE-2022-31524, it is recommended to update the Purestorage Pure Swagger software to a version that is not affected by the vulnerability.