CVE-2022-42706: Path Traversal
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-42706?
CVE-2022-42706 is an issue discovered in Sangoma Asterisk that allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
How does CVE-2022-42706 impact Sangoma Asterisk?
CVE-2022-42706 allows an attacker to access files outside of the asterisk configuration directory, potentially leading to unauthorized access or disclosure of sensitive information.
What is the severity of CVE-2022-42706?
CVE-2022-42706 has a severity rating of 4.9 (medium).
How can I fix CVE-2022-42706?
To fix CVE-2022-42706, it is recommended to upgrade Sangoma Asterisk to the latest version available as per the provided references.
Where can I find more information about CVE-2022-42706?
You can find more information about CVE-2022-42706 in the references provided: [link1](https://issues.asterisk.org/jira/browse/ASTERISK-30176), [link2](https://downloads.asterisk.org/pub/security/AST-2022-009.html), [link3](https://git.asterisk.org/gitweb/?p=asterisk/asterisk.git;a=commit;h=81f10e847efdbe8ec264062ee234e1098c29b3f6).