CVE-2022-31530: Path Traversal
Published Jul 11, 2022
·Updated
The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask sendfile function is used unsafely.
Affected Software
1 affected component
Csm Server Project Csm Server<=3.5
Event History
Jul 11, 2022
CVE Published
via MITRE·12:56 AM
Data Sourced
via MITRE·12:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-31530?
CVE-2022-31530 is classified as a medium severity vulnerability due to its potential for absolute path traversal.
2
How can I mitigate CVE-2022-31530?
To mitigate CVE-2022-31530, consider updating to a version higher than 3.5 and ensure safe usage of the Flask send_file function.
3
Which versions are affected by CVE-2022-31530?
CVE-2022-31530 affects csm_server versions up to and including 3.5.
4
What attack vectors are associated with CVE-2022-31530?
CVE-2022-31530 can be exploited through crafted requests that can lead to unauthorized file access.
5
Which software is impacted by CVE-2022-31530?
CVE-2022-31530 impacts the csm_server_project software, specifically versions up to 3.5.