First published: Thu Oct 06 2022(Updated: )
Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
Credit: security@huntr.dev security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Ikus-soft Rdiffweb | <2.4.10 | |
pip/rdiffweb | <2.4.10 | 2.4.10 |
<2.4.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3389 is a vulnerability that allows an attacker to traverse the file system and access files outside of the intended directory.
The severity of CVE-2022-3389 is high with a CVSS score of 7.5.
CVE-2022-3389 affects ikus060/rdiffweb prior to version 2.4.10.
To fix CVE-2022-3389, update ikus060/rdiffweb to version 2.4.10 or later.
You can find more information about CVE-2022-3389 in the references: [GitHub Commit](https://github.com/ikus060/rdiffweb/commit/323383d1db656f1b1291be529947bd943a6b0e99), [Huntr Dev Bounty](https://huntr.dev/bounties/f7d2a6ab-2faf-4719-bdb6-e4e5d6065752)