CVE-2023-42487: Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published Sep 27, 2023
·Updated
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Software
1 affected component
Soundminer Soundminer<2.01
Remediation
Information
Upgrade to version 2.01
Event History
Sep 27, 2023
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-42487?
CVE-2023-42487 is a vulnerability in Soundminer that allows an attacker to access files outside of the restricted directory.
2
How does CWE-22 affect Soundminer?
CWE-22, also known as Path Traversal, affects Soundminer by allowing attackers to bypass restrictions and access files outside of the intended directory.
3
What is the severity of CVE-2023-42487?
CVE-2023-42487 has a severity rating of 7.5, which is considered high.
4
Which version of Soundminer is affected by CVE-2023-42487?
Soundminer version up to and excluding 2.01 is affected by CVE-2023-42487.
5
How can I fix the CVE-2023-42487 vulnerability in Soundminer?
To fix the CVE-2023-42487 vulnerability in Soundminer, it is recommended to update to a version beyond 2.01.