CVE-2022-45866: Path Traversal
Published Nov 23, 2022
·Updated
qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.
Affected Software
4 affected components
Qpress Project Qpress<11.3
Fedoraproject Fedora=35
Fedoraproject Fedora=36
Fedoraproject Fedora=37
Event History
Nov 23, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-45866?
CVE-2022-45866 has been assessed as critical due to the possibility of directory traversal vulnerabilities allowing unauthorized access to sensitive files.
2
How do I fix CVE-2022-45866?
To fix CVE-2022-45866, upgrade to version 11.3 or later of qpress.
3
What products are affected by CVE-2022-45866?
CVE-2022-45866 affects qpress prior to version 11.3 and is also used in products like Percona XtraBackup.
4
What type of vulnerability is CVE-2022-45866?
CVE-2022-45866 is a directory traversal vulnerability that allows attackers to access files outside of designated directories.
5
Which versions of Fedora are impacted by CVE-2022-45866?
CVE-2022-45866 impacts Fedora versions 35, 36, and 37.