First published: Thu May 11 2023(Updated: )
spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Spring Boot Actuator Logview | =0.2.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-29986 has a high severity level due to the potential for remote directory traversal attacks.
To fix CVE-2023-29986, upgrade spring-boot-actuator-logview to version 0.2.14 or later which addresses this vulnerability.
CVE-2023-29986 allows an attacker to access files outside the intended directory, potentially exposing sensitive information.
CVE-2023-29986 specifically affects the spring-boot-actuator-logview version 0.2.13.
As of now, there are no confirmed reports of active exploitation of CVE-2023-29986, but it is advisable to mitigate the risk immediately.